Ruby Improper Neutralization of Special Elements used in a Command (Command Injection) Vulnerability - CVE-2021-31799 - Vulnerability Database
Ruby Improper Neutralization of Special Elements used in a Command (Command Injection) Vulnerability - CVE-2021-31799
Critical
Reference:
CVE-2021-31799
Title:
Ruby Improper Neutralization of Special Elements used in a Command (Command Injection) Vulnerability
Overview:
In RDoc 3.11 through 6.x before 6.3.1 as distributed with Ruby through 3.0.1 it is possible to execute arbitrary code via and tags in a filename.