Sha256: 291a47e627aa6ee4e995e79f7d4fa5b3a2687379ea3562a987bfb95603843e31

Contents?: true

Size: 536 Bytes

Versions: 1

Compression:

Stored size: 536 Bytes

Contents

---
gem: rubygems-update
library: rubygems
cve: 2019-8322
url: https://blog.rubygems.org/2019/03/05/security-advisories-2019-03.html
title: Escape sequence injection vulnerability in gem owner
date: 2019-03-05
description: |
  An issue was discovered in RubyGems 2.6 and later through 3.0.2. The gem
  owner command outputs the contents of the API response directly to stdout.
  Therefore, if the response is crafted, escape sequence injection may occur.
unaffected_versions:
  - "< 2.6"
patched_versions:
  - ">= 3.0.3"
  - "~> 2.7.9"

Version data entries

1 entries across 1 versions & 1 rubygems

Version Path
bundler-audit-0.7.0.1 data/ruby-advisory-db/gems/rubygems-update/CVE-2019-8322.yml