REDHAT-BUG-1692514: Low severity rubygems vulnerability
An issue was discovered in RubyGems 2.6 and later through 3.0.2. Since Gem::UserInteraction#verbose calls say without escaping, escape sequence injection is possible.
Upstream patch:
https://bugs.ruby-lang.org/attachments/7669
References:
https://www.ruby-lang.org/en/news/2019/03/05/multiple-vulnerabilities-in-rubygems/ https://blog.rubygems.org/2019/03/05/security-advisories-2019-03.html
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-1692514?
The severity of REDHAT-BUG-1692514 is classified as moderate due to the potential for escape sequence injection.
How do I fix REDHAT-BUG-1692514?
To fix REDHAT-BUG-1692514, update RubyGems to a version later than 3.0.2.
Which versions are affected by REDHAT-BUG-1692514?
REDHAT-BUG-1692514 affects RubyGems versions from 2.6 up to and including 3.0.2.
What impact does REDHAT-BUG-1692514 have on the system?
REDHAT-BUG-1692514 can lead to escape sequence injection, potentially allowing for unexpected command execution.
Who is responsible for addressing REDHAT-BUG-1692514?
The RubyGems maintainers are responsible for addressing and patching REDHAT-BUG-1692514.