CVE-2019-8323: High severity rubygems vulnerability
An issue was discovered in RubyGems 2.6 and later through 3.0.2. Gem::GemcutterUtilities#withresponse may output the API response to stdout as it is. Therefore, if the API side modifies the response, escape sequence injection may occur.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2019-8323.
What is the severity of CVE-2019-8323?
The severity of CVE-2019-8323 is high (7.5).
What is the affected software?
The affected software includes RubyGems 2.6 through 3.0.2, rubygems-update version 2.6.0 through 2.7.9, Rubygems Rubygems version 2.6.0 through 3.0.2, Debian Debian Linux version 9.0, openSUSE Leap versions 15.0 and 15.1.
What is the description of CVE-2019-8323?
CVE-2019-8323 is a vulnerability in RubyGems that allows for escape sequence injection due to the Gem::GemcutterUtilities#with_response method outputting the API response to stdout.
How can I fix CVE-2019-8323?
To fix CVE-2019-8323, update to RubyGems version 3.0.2 or use rubygems-update version 2.7.9.