CVE-2021-31799

CVSS v3.1 7 (High)
70% Progress
CVSS v2.0 4.4 (Medium)
44% Progress
EPSS 0.06 % (28th)
0.06% Progress
Affected Products 4
Advisories 29

In RDoc 3.11 through 6.x before 6.3.1, as distributed with Ruby through 3.0.1, it is possible to execute arbitrary code via | and tags in a filename.

Weaknesses
CWE-78
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE Status
PUBLISHED
CNA
MITRE
Published Date
2021-07-30 14:15:16
(3 years ago)
Updated Date
2024-01-05 14:15:46
(8 months ago)

Affected Products

Loading...
Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Debian Linux 9.0 cpe:2.3:o:debian:debian_linux:9.0
  Debian Linux 10.0 cpe:2.3:o:debian:debian_linux:10.0

Configuration #2

AND
    CPE23 From Up To
OR  
  Ruby-lang Rdoc for Ruby from 3.11 version and prior 6.3.1 version cpe:2.3:a:ruby-lang:rdoc::*:*:*:*:ruby >= 3.11 < 6.3.1
OR  
  Running on/with
  Ruby-lang Ruby 3.0.1 and prior versions cpe:2.3:a:ruby-lang:ruby <= 3.0.1

Configuration #3

    CPE23 From Up To
  Oracle Jd Edwards Enterpriseone Tools prior 9.2.6.1 version cpe:2.3:a:oracle:jd_edwards_enterpriseone_tools < 9.2.6.1
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...