← back
CVE-2017-0899CWE-150

CVE-2017-0899

8Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackepss 11%
exploitation probability
11%top 5% of all CVEs
observed exploitation
nono source reports it
RubyGems version 2.6.12 and earlier is vulnerable to maliciously crafted gem specifications that include terminal escape characters. Printing the gem specification would execute terminal escape sequences.
Affected products
HackerOne · RubyGems