CVE-2020-8130OS Command Injection in Rake

CWE-78OS Command Injection10 documents8 sources
Severity
6.4MEDIUMNVD
EPSS
0.1%
top 65.57%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 24
Latest updateMar 23

Description

There is an OS command injection vulnerability in Ruby Rake < 12.3.3 in Rake::FileList when supplying a filename that begins with the pipe character `|`.

CVSS vector

CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:HExploitability: 0.5 | Impact: 5.9

Affected Packages7 packages

NVDruby-lang/rake< 12.3.3
RubyGemsruby-lang/rake< 12.3.3
Debianruby-lang/rake< 12.3.3-1+3
debiandebian/rake< rake 12.3.3-1 (bookworm)
CVEListV5https/github.com_ruby_rubyFixed in Rake 12.3.3

Also affects: Debian Linux 8.0, Fedora 30, 31, Ubuntu Linux 16.04, 18.04, 19.10

Patches

🔴Vulnerability Details

3
GHSA
OS Command Injection in Rake2020-02-28
OSV
OS Command Injection in Rake2020-02-28
OSV
CVE-2020-8130: There is an OS command injection vulnerability in Ruby Rake < 122020-02-24

📋Vendor Advisories

4
Ubuntu
Rake vulnerability2020-03-03
Microsoft
There is an OS command injection vulnerability in Ruby Rake < 12.3.3 in Rake::FileList when supplying a filename that begins with the pipe character `|`.2020-02-11
Debian
CVE-2020-8130: rake - There is an OS command injection vulnerability in Ruby Rake < 12.3.3 in Rake::Fi...2020
Red Hat
rake: OS Command Injection via egrep in Rake::FileList2019-08-29

💬Community

2
Bugzilla
CVE-2020-8130 rubygem-rake: rake: OS Command Injection via egrep in Rake::FileList [fedora-all]2020-03-23
Bugzilla
CVE-2020-8130 rake: OS Command Injection via egrep in Rake::FileList2020-03-23
CVE-2020-8130 — OS Command Injection in Ruby-lang Rake | cvebase