{"id":"GHSA-hxx6-p24v-wg8c","summary":"Curl Gem insufficient URL escaping command injection","details":"`lib/curl.rb` in the Curl Gem for Ruby allows remote attackers to execute arbitrary commands via shell metacharacters in a URL.","aliases":["CVE-2013-2617"],"modified":"2024-12-05T05:39:00.179456Z","published":"2017-10-24T18:33:37Z","database_specific":{"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2020-06-16T21:41:31Z","nvd_published_at":null,"cwe_ids":["CWE-94"]},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2013-2617"},{"type":"WEB","url":"https://github.com/rubysec/ruby-advisory-db/blob/master/gems/curl/CVE-2013-2617.yml"},{"type":"PACKAGE","url":"https://github.com/tggo/curl"},{"type":"WEB","url":"http://packetstormsecurity.com/files/120778/Ruby-Gem-Curl-Command-Execution.html"},{"type":"WEB","url":"http://seclists.org/fulldisclosure/2013/Mar/124"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2013/03/19/9"}],"affected":[{"package":{"name":"curl","ecosystem":"RubyGems","purl":"pkg:gem/curl"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"0.0.9"}]}],"versions":["0.0.3","0.0.4","0.0.5","0.0.6","0.0.7","0.0.8","0.0.9"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2017/10/GHSA-hxx6-p24v-wg8c/GHSA-hxx6-p24v-wg8c.json"}}],"schema_version":"1.9.0"}