REDHAT-BUG-1692519: Low severity rubygems vulnerability
An issue was discovered in RubyGems 2.6 and later through 3.0.2. Gem::GemcutterUtilities#withresponse may output the API response to stdout as it is. Therefore, if the API side modifies the response, escape sequence injection may occur.
Upstream patch:
https://bugs.ruby-lang.org/attachments/7669
References:
https://www.ruby-lang.org/en/news/2019/03/05/multiple-vulnerabilities-in-rubygems/ https://blog.rubygems.org/2019/03/05/security-advisories-2019-03.html
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-1692519?
The severity of REDHAT-BUG-1692519 is considered significant due to potential escape sequence injection.
How do I fix REDHAT-BUG-1692519?
To fix REDHAT-BUG-1692519, update RubyGems to version 3.0.3 or later.
What versions are affected by REDHAT-BUG-1692519?
RubyGems versions between 2.6 and 3.0.2 are affected by REDHAT-BUG-1692519.
What kind of issue is REDHAT-BUG-1692519?
REDHAT-BUG-1692519 is an issue that involves potential escape sequence injection through API response handling.
Who should be concerned about REDHAT-BUG-1692519?
Developers using RubyGems versions 2.6 through 3.0.2 should be concerned about REDHAT-BUG-1692519.