CVE-2017-0899
8Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackepss 11%
exploitation probability
11%top 5% of all CVEs
observed exploitation
nono source reports it
RubyGems version 2.6.12 and earlier is vulnerable to maliciously crafted gem specifications that include terminal escape characters. Printing the gem specification would execute terminal escape sequences.
Affected products
HackerOne · RubyGemsReferences
http://blog.rubygems.org/2017/08/27/2.6.13-released.htmlhttps://access.redhat.com/errata/RHSA-2017:3485https://access.redhat.com/errata/RHSA-2018:0378https://access.redhat.com/errata/RHSA-2018:0583https://access.redhat.com/errata/RHSA-2018:0585https://github.com/rubygems/rubygems/commit/1bcbc7fe637b03145401ec9c094066285934a7f1https://github.com/rubygems/rubygems/commit/ef0aa611effb5f54d40c7fba6e8235eb43c5a491https://hackerone.com/reports/226335https://lists.debian.org/debian-lts-announce/2018/07/msg00012.htmlhttps://security.gentoo.org/glsa/201710-01https://www.debian.org/security/2017/dsa-3966http://www.securityfocus.com/bid/100576