CVE-2019-8325: High severity rubygems vulnerability
An issue was discovered in RubyGems 2.6 and later through 3.0.2. Since Gem::CommandManager#run calls alerterror without escaping, escape sequence injection is possible. (There are many ways to cause an error.)
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-8325?
The severity of CVE-2019-8325 is high, with a CVSS score of 7.5.
How does CVE-2019-8325 affect RubyGems?
CVE-2019-8325 affects RubyGems version 2.6 and later through 3.0.2.
What is the remediation for CVE-2019-8325 in RubyGems?
The remediation for CVE-2019-8325 in RubyGems is to update to version 3.0.2 or higher.
Which operating systems are affected by CVE-2019-8325?
CVE-2019-8325 affects openSUSE Leap 15.0 and 15.1, as well as Debian Linux 9.0.
Where can I find more information about CVE-2019-8325?
You can find more information about CVE-2019-8325 at the following references: [NVD](https://nvd.nist.gov/vuln/detail/CVE-2019-8325), [Debian LTS Announce](https://lists.debian.org/debian-lts-announce/2020/08/msg00027.html), [openSUSE Security Announce](http://lists.opensuse.org/opensuse-security-announce/2019-07/msg00036.html).