Sha256: 8d5ccefbcba07ac3bf4f52ba978736b3b0632ba7abc086ffb277e7a409045cfe

Contents?: true

Size: 411 Bytes

Versions: 1

Compression:

Stored size: 411 Bytes

Contents

---
gem: bibtex-ruby
cve: 2019-10780
ghsa: c5r5-7pfh-6qg6
url: https://github.com/advisories/GHSA-c5r5-7pfh-6qg6
date: 2020-02-14
title: OS command injection in BibTeX-Ruby
description: |
  BibTeX-ruby before 5.1.0 allows shell command injection due to unsanitized
  user input being passed directly to the built-in Ruby Kernel.open method through
  BibTeX.open.

cvss_v3: 9.8

patched_versions:
  - ">= 5.1.0"

Version data entries

1 entries across 1 versions & 1 rubygems

Version Path
bundler-audit-0.7.0.1 data/ruby-advisory-db/gems/bibtex-ruby/CVE-2019-10780.yml