CVE-2017-0899 Vulnerability Details
/
/
/
CVE-2017-0899 Metadata Quick Info
CVE Published: 31/08/2017 |
CVE Updated: 17/09/2024 |
CVE Year: 2017
Source: hackerone |
Vendor: HackerOne |
Product: RubyGems
Status : PUBLISHED
CVE-2017-0899 Description
RubyGems version 2.6.12 and earlier is vulnerable to maliciously crafted gem specifications that include terminal escape characters. Printing the gem specification would execute terminal escape sequences.
Metrics
CVSS Version: 3.1 |
Base Score: n/a
Vector: n/a
l➤ Exploitability Metrics:
Attack Vector (AV)*
Attack Complexity (AC)*
Privileges Required (PR)*
User Interaction (UI)*
Scope (S)*
l➤ Impact Metrics:
Confidentiality Impact (C)*
Integrity Impact (I)*
Availability Impact (A)*
Weakness Enumeration (CWE)
CWE-ID: CWE-150
CWE Name: Improper Neutralization of Escape, Meta, or Control Sequences (CWE-150)
Source: HackerOne
Common Attack Pattern Enumeration and Classification (CAPEC)
CAPEC-ID:
CAPEC Description:
Source: NVD (National Vulnerability Database).