The perform_request
function in /lib/echor/backplane.rb
in echor 0.1.6 Ruby Gem allows local users to inject arbitrary code by adding a semi-colon in their username or password.
{ "nvd_published_at": "2018-02-02T21:29:00Z", "cwe_ids": [ "CWE-77" ], "severity": "HIGH", "github_reviewed": true, "github_reviewed_at": "2023-06-09T23:07:05Z" }