RubyGems Improper Neutralization of Argument Delimiters in a Command (Argument Injection) Vulnerability - CVE-2019-8321 - Vulnerability Database
RubyGems Improper Neutralization of Argument Delimiters in a Command (Argument Injection) Vulnerability - CVE-2019-8321
High
Reference:
CVE-2019-8321
Title:
RubyGems Improper Neutralization of Argument Delimiters in a Command (Argument Injection) Vulnerability
Overview:
An issue was discovered in RubyGems 2.6 and later through 3.0.2. Since Gem::UserInteractionverbose calls say without escaping escape sequence injection is possible.