CVE Vulnerabilities

CVE-2019-8325

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

Published: Jun 17, 2019 | Modified: Aug 19, 2020
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
5.3 LOW
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Ubuntu
MEDIUM

An issue was discovered in RubyGems 2.6 and later through 3.0.2. Since Gem::CommandManager#run calls alert_error without escaping, escape sequence injection is possible. (There are many ways to cause an error.)

Weakness

The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.

Affected Software

Name Vendor Start Version End Version
Rubygems Rubygems 2.6.0 (including) 3.0.2 (including)
CloudForms Management Engine 5.10 RedHat cfme-0:5.10.5.1-1.el7cf *
CloudForms Management Engine 5.10 RedHat cfme-amazon-smartstate-0:5.10.5.1-1.el7cf *
CloudForms Management Engine 5.10 RedHat cfme-appliance-0:5.10.5.1-1.el7cf *
CloudForms Management Engine 5.10 RedHat cfme-gemset-0:5.10.5.1-1.el7cf *
CloudForms Management Engine 5.10 RedHat ruby-0:2.4.6-91.el7cf *
Red Hat Enterprise Linux 7 RedHat ruby-0:2.0.0.648-35.el7_6 *
Red Hat Enterprise Linux 7.4 Advanced Update Support RedHat ruby-0:2.0.0.648-37.el7_4 *
Red Hat Enterprise Linux 7.4 Telco Extended Update Support RedHat ruby-0:2.0.0.648-37.el7_4 *
Red Hat Enterprise Linux 7.4 Update Services for SAP Solutions RedHat ruby-0:2.0.0.648-37.el7_4 *
Red Hat Enterprise Linux 8 RedHat ruby:2.5-8010020190711131821.cdc1202b *
Red Hat Software Collections for Red Hat Enterprise Linux 6 RedHat rh-ruby24-ruby-0:2.4.6-92.el6 *
Red Hat Software Collections for Red Hat Enterprise Linux 7 RedHat rh-ruby25-ruby-0:2.5.5-7.el7 *
Red Hat Software Collections for Red Hat Enterprise Linux 7 RedHat rh-ruby24-ruby-0:2.4.6-92.el7 *
Red Hat Software Collections for Red Hat Enterprise Linux 7.4 EUS RedHat rh-ruby25-ruby-0:2.5.5-7.el7 *
Red Hat Software Collections for Red Hat Enterprise Linux 7.4 EUS RedHat rh-ruby24-ruby-0:2.4.6-92.el7 *
Red Hat Software Collections for Red Hat Enterprise Linux 7.5 EUS RedHat rh-ruby25-ruby-0:2.5.5-7.el7 *
Red Hat Software Collections for Red Hat Enterprise Linux 7.5 EUS RedHat rh-ruby24-ruby-0:2.4.6-92.el7 *
Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUS RedHat rh-ruby25-ruby-0:2.5.5-7.el7 *
Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUS RedHat rh-ruby24-ruby-0:2.4.6-92.el7 *
Jruby Ubuntu bionic *
Jruby Ubuntu cosmic *
Jruby Ubuntu disco *
Jruby Ubuntu esm-apps/bionic *
Jruby Ubuntu trusty/esm *
Ruby1.9.1 Ubuntu trusty *
Ruby2.0 Ubuntu trusty *
Ruby2.3 Ubuntu xenial *
Ruby2.5 Ubuntu bionic *
Ruby2.5 Ubuntu cosmic *
Ruby2.5 Ubuntu disco *
Ruby2.5 Ubuntu eoan *

Potential Mitigations

References