RubyGems Improper Neutralization of Argument Delimiters in a Command (Argument Injection) Vulnerability - CVE-2019-8321 - Vulnerability Database

RubyGems Improper Neutralization of Argument Delimiters in a Command (Argument Injection) Vulnerability - CVE-2019-8321

High
Reference: CVE-2019-8321
Title: RubyGems Improper Neutralization of Argument Delimiters in a Command (Argument Injection) Vulnerability
Overview:

An issue was discovered in RubyGems 2.6 and later through 3.0.2. Since Gem::UserInteractionverbose calls say without escaping escape sequence injection is possible.