{"id":"GHSA-77xq-7c6p-6xp6","summary":"RubyGem openshift-origin-controller is vulnerable to command injection","details":"rubygem-openshift-origin-controller: API can be used to create applications via cartridge_cache.rb URI.prase() to perform command injection","aliases":["CVE-2013-2095"],"modified":"2024-02-16T08:06:58.193963Z","published":"2022-05-05T00:29:09Z","database_specific":{"github_reviewed_at":"2023-08-28T23:21:08Z","nvd_published_at":"2019-12-10T14:15:00Z","cwe_ids":["CWE-74"],"severity":"CRITICAL","github_reviewed":true},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2013-2095"},{"type":"WEB","url":"https://access.redhat.com/security/cve/cve-2013-2095"},{"type":"WEB","url":"https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2013-2095"},{"type":"PACKAGE","url":"https://github.com/openshift/origin-server"},{"type":"WEB","url":"https://github.com/rubysec/ruby-advisory-db/blob/master/gems/openshift-origin-controller/CVE-2013-2095.yml"}],"affected":[{"package":{"name":"openshift-origin-controller","ecosystem":"RubyGems","purl":"pkg:gem/openshift-origin-controller"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"1.3.4"}]}],"versions":["1.3.2","1.3.3","1.3.4"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-77xq-7c6p-6xp6/GHSA-77xq-7c6p-6xp6.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}