{"id":"GHSA-c43v-hrmg-56r4","summary":"Cocaine Gem OS Command Injection vulnerability","details":"The Cocaine gem 0.4.0 through 0.5.2 for Ruby allows context-dependent attackers to execute arbitrary commands via a crafted has object, related to recursive variable interpolation.","aliases":["CVE-2013-4457"],"modified":"2024-12-03T06:08:14.516736Z","published":"2017-10-24T18:33:37Z","database_specific":{"github_reviewed_at":"2020-06-16T21:30:11Z","nvd_published_at":"2013-11-02T18:55:03Z","cwe_ids":["CWE-78"],"severity":"MODERATE","github_reviewed":true},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2013-4457"},{"type":"PACKAGE","url":"https://github.com/thoughtbot/cocaine"},{"type":"WEB","url":"https://github.com/thoughtbot/cocaine/blob/master/NEWS.md"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2013/10/22/10"}],"affected":[{"package":{"name":"cocaine","ecosystem":"RubyGems","purl":"pkg:gem/cocaine"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0.4.0"},{"fixed":"0.5.3"}]}],"versions":["0.4.0","0.4.1","0.4.2","0.5.0","0.5.1","0.5.2"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2017/10/GHSA-c43v-hrmg-56r4/GHSA-c43v-hrmg-56r4.json"}}],"schema_version":"1.9.0"}