CVE-2017-0899 — Improper Neutralization of Escape, Meta, or Control Sequences in Rubygems
Severity
9.8CRITICALNVD
OSV9.1
EPSS
7.4%
top 8.27%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedAug 31
Latest updateMay 13
Description
RubyGems version 2.6.12 and earlier is vulnerable to maliciously crafted gem specifications that include terminal escape characters. Printing the gem specification would execute terminal escape sequences.
CVSS vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9
Affected Packages6 packages
Also affects: Debian Linux 8.0, 9.0, Enterprise Linux 7.4, 7.6, 7.5
Patches
🔴Vulnerability Details
5📋Vendor Advisories
3🕵️Threat Intelligence
1Fortinet
▶