{"id":"GHSA-9wcm-rrvh-qjc8","summary":"High severity vulnerability that affects colorscore","details":"Withdrawn, accidental duplicate publish.\n\nThe initialize method in the Histogram class in lib/colorscore/histogram.rb in the colorscore gem before 0.0.5 for Ruby allows context-dependent attackers to execute arbitrary code via shell metacharacters in the (1) image_path, (2) colors, or (3) depth variable.","modified":"2024-12-02T05:44:34.107749Z","published":"2018-08-15T20:03:53Z","withdrawn":"2020-06-17T15:14:43Z","database_specific":{"cwe_ids":[],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2020-06-17T15:14:43Z","nvd_published_at":null},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2015-7541"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-9wcm-rrvh-qjc8"}],"affected":[{"package":{"name":"colorscore","ecosystem":"RubyGems","purl":"pkg:gem/colorscore"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.0.5"}]}],"versions":["0.0.1","0.0.2","0.0.3","0.0.4"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2018/08/GHSA-9wcm-rrvh-qjc8/GHSA-9wcm-rrvh-qjc8.json"}}],"schema_version":"1.9.0"}