{"id":"GHSA-76wm-422q-92mq","summary":"Code injection in RubyGems","details":"An issue was discovered in RubyGems 2.6 and later through 3.0.2. A crafted gem with a multi-line name is not handled correctly. Therefore, an attacker could inject arbitrary code to the stub line of gemspec, which is eval-ed by code in ensure_loadable_spec during the preinstall check.","aliases":["CVE-2019-8324"],"modified":"2024-02-16T08:05:58.997983Z","published":"2019-06-20T16:06:11Z","database_specific":{"github_reviewed":true,"nvd_published_at":null,"severity":"HIGH","cwe_ids":["CWE-94"],"github_reviewed_at":"2019-06-20T16:01:22Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2019-8324"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2019:1972"},{"type":"WEB","url":"https://blog.rubygems.org/2019/03/05/security-advisories-2019-03.html"},{"type":"WEB","url":"https://github.com/rubysec/ruby-advisory-db/blob/master/gems/rubygems-update/CVE-2019-8324.yml"},{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2020/08/msg00027.html"},{"type":"WEB","url":"http://lists.opensuse.org/opensuse-security-announce/2019-07/msg00036.html"}],"affected":[{"package":{"name":"rubygems-update","ecosystem":"RubyGems","purl":"pkg:gem/rubygems-update"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.6.0"},{"fixed":"2.7.9"}]}],"versions":["2.6.0","2.6.1","2.6.10","2.6.11","2.6.12","2.6.13","2.6.14","2.6.2","2.6.3","2.6.4","2.6.5","2.6.6","2.6.7","2.6.8","2.6.9","2.7.0","2.7.1","2.7.2","2.7.3","2.7.4","2.7.4.pre1","2.7.5","2.7.6","2.7.7","2.7.8"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2019/06/GHSA-76wm-422q-92mq/GHSA-76wm-422q-92mq.json"}},{"package":{"name":"rubygems-update","ecosystem":"RubyGems","purl":"pkg:gem/rubygems-update"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"3.0.0"},{"fixed":"3.0.2"}]}],"versions":["3.0.0","3.0.1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2019/06/GHSA-76wm-422q-92mq/GHSA-76wm-422q-92mq.json"}}],"schema_version":"1.7.3","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"}]}