CVE Vulnerabilities

CVE-2019-8325

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

Published: Jun 17, 2019 | Modified: Nov 21, 2024
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
5.3 LOW
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

An issue was discovered in RubyGems 2.6 and later through 3.0.2. Since Gem::CommandManager#run calls alert_error without escaping, escape sequence injection is possible. (There are many ways to cause an error.)

Weakness

The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.

Affected Software

NameVendorStart VersionEnd Version
RubygemsRubygems2.6.0 (including)3.0.2 (including)
CloudForms Management Engine 5.10RedHatcfme-0:5.10.5.1-1.el7cf*
CloudForms Management Engine 5.10RedHatcfme-amazon-smartstate-0:5.10.5.1-1.el7cf*
CloudForms Management Engine 5.10RedHatcfme-appliance-0:5.10.5.1-1.el7cf*
CloudForms Management Engine 5.10RedHatcfme-gemset-0:5.10.5.1-1.el7cf*
CloudForms Management Engine 5.10RedHatruby-0:2.4.6-91.el7cf*
Red Hat Enterprise Linux 7RedHatruby-0:2.0.0.648-35.el7_6*
Red Hat Enterprise Linux 7.4 Advanced Update SupportRedHatruby-0:2.0.0.648-37.el7_4*
Red Hat Enterprise Linux 7.4 Telco Extended Update SupportRedHatruby-0:2.0.0.648-37.el7_4*
Red Hat Enterprise Linux 7.4 Update Services for SAP SolutionsRedHatruby-0:2.0.0.648-37.el7_4*
Red Hat Enterprise Linux 8RedHatruby:2.5-8010020190711131821.cdc1202b*
Red Hat Software Collections for Red Hat Enterprise Linux 6RedHatrh-ruby24-ruby-0:2.4.6-92.el6*
Red Hat Software Collections for Red Hat Enterprise Linux 7RedHatrh-ruby25-ruby-0:2.5.5-7.el7*
Red Hat Software Collections for Red Hat Enterprise Linux 7RedHatrh-ruby24-ruby-0:2.4.6-92.el7*
Red Hat Software Collections for Red Hat Enterprise Linux 7.4 EUSRedHatrh-ruby25-ruby-0:2.5.5-7.el7*
Red Hat Software Collections for Red Hat Enterprise Linux 7.4 EUSRedHatrh-ruby24-ruby-0:2.4.6-92.el7*
Red Hat Software Collections for Red Hat Enterprise Linux 7.5 EUSRedHatrh-ruby25-ruby-0:2.5.5-7.el7*
Red Hat Software Collections for Red Hat Enterprise Linux 7.5 EUSRedHatrh-ruby24-ruby-0:2.4.6-92.el7*
Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUSRedHatrh-ruby25-ruby-0:2.5.5-7.el7*
Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUSRedHatrh-ruby24-ruby-0:2.4.6-92.el7*
JrubyUbuntubionic*
JrubyUbuntucosmic*
JrubyUbuntudisco*
JrubyUbuntuesm-apps/bionic*
JrubyUbuntuesm-infra-legacy/trusty*
JrubyUbuntutrusty/esm*
Ruby1.9.1Ubuntutrusty*
Ruby2.0Ubuntutrusty*
Ruby2.3Ubuntuesm-infra/xenial*
Ruby2.3Ubuntuxenial*
Ruby2.5Ubuntubionic*
Ruby2.5Ubuntucosmic*
Ruby2.5Ubuntudisco*
Ruby2.5Ubuntueoan*
Ruby2.5Ubuntuesm-infra/bionic*

Potential Mitigations

References