Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:20060
HistoryMay 16, 2019 - 3:48 a.m.

Escape Sequence Injection

2019-05-1603:48:47
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
10

0.002 Low

EPSS

Percentile

58.3%

Ruby is vulnerable to escape sequence injection. This exists in the function Gem::GemcutterUtilities#with_response of the component API Response Handler. Gem::GemcutterUtilities#with_response may output the API response to stdout without any change. Modifications in the response from API side may cause escape sequence injection vulnerability.