{"id":"GHSA-m6f7-46hw-grcj","summary":"Creme Fraiche contains OS Command Injection","details":"The set_meta_data function in lib/cremefraiche.rb in the Creme Fraiche gem before 0.6.1 for Ruby allows remote attackers to execute arbitrary commands via shell metacharacters in the file name of an email attachment.  NOTE: some of these details are obtained from third party information.","aliases":["CVE-2013-2090"],"modified":"2023-11-08T03:57:17.360593Z","published":"2017-10-24T18:33:37Z","database_specific":{"cwe_ids":["CWE-78"],"severity":"CRITICAL","github_reviewed":true,"github_reviewed_at":"2020-06-16T21:45:09Z","nvd_published_at":"2014-05-27T14:55:06Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2013-2090"},{"type":"WEB","url":"http://packetstormsecurity.com/files/121635/Ruby-Gem-Creme-Fraiche-0.6-Command-Injection.html"},{"type":"WEB","url":"http://www.vapid.dhs.org/advisories/cremefraiche-cmd-inj.html"}],"affected":[{"package":{"name":"cremefraiche","ecosystem":"RubyGems","purl":"pkg:gem/cremefraiche"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.6.1"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2017/10/GHSA-m6f7-46hw-grcj/GHSA-m6f7-46hw-grcj.json"}}],"schema_version":"1.9.0"}