CVE-2021-31799OS Command Injection in Rdoc

Severity
7.0HIGHNVD
EPSS
0.4%
top 42.40%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 30
Latest updateSep 1

Description

In RDoc 3.11 through 6.x before 6.3.1, as distributed with Ruby through 3.0.1, it is possible to execute arbitrary code via | and tags in a filename.

CVSS vector

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.0 | Impact: 5.9

Affected Packages3 packages

NVDruby-lang/rdoc3.116.3.1
RubyGemsruby-lang/rdoc3.116.1.2.1+2

Also affects: Debian Linux 10.0, 9.0

Patches

🔴Vulnerability Details

5
GHSA
Arbitrary Code Execution in Rdoc2021-09-01
OSV
Arbitrary Code Execution in Rdoc2021-09-01
OSV
CVE-2021-31799: In RDoc 32021-07-30
CVEList
CVE-2021-31799: In RDoc 32021-07-29
OSV
ruby2.3, ruby2.5, ruby2.7 vulnerabilities2021-07-21

📋Vendor Advisories

3
Ubuntu
Ruby vulnerabilities2021-07-21
Red Hat
rubygem-rdoc: Command injection vulnerability in RDoc2021-05-02
Debian
CVE-2021-31799: ruby2.7 - In RDoc 3.11 through 6.x before 6.3.1, as distributed with Ruby through 3.0.1, i...2021
CVE-2021-31799 — OS Command Injection in Ruby-lang Rdoc | cvebase