CVE-2019-8323

HIGH7.5EPSS 0.33%

RubyGems Escape sequence injection vulnerability in api response handling

Published: 6/20/2019Modified: 11/19/2025
Also known as:GHSA-3h4r-pjv6-cph9ALPINE-CVE-2019-8323DEBIAN-CVE-2019-8323

Description

An issue was discovered in RubyGems 2.6 and later through 3.0.2. Gem::GemcutterUtilities#with_response may output the API response to stdout as it is. Therefore, if the API side modifies the response, escape sequence injection may occur.

Affected packages (4)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1HIGH7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

References (8)