GHSA-c43v-hrmg-56r4

Suggest an improvement
Source
https://github.com/advisories/GHSA-c43v-hrmg-56r4
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2017/10/GHSA-c43v-hrmg-56r4/GHSA-c43v-hrmg-56r4.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-c43v-hrmg-56r4
Aliases
  • CVE-2013-4457
Published
2017-10-24T18:33:37Z
Modified
2024-12-03T06:08:14.516736Z
Summary
Cocaine Gem OS Command Injection vulnerability
Details

The Cocaine gem 0.4.0 through 0.5.2 for Ruby allows context-dependent attackers to execute arbitrary commands via a crafted has object, related to recursive variable interpolation.

Database specific
{
    "nvd_published_at": "2013-11-02T18:55:03Z",
    "cwe_ids": [
        "CWE-78"
    ],
    "severity": "MODERATE",
    "github_reviewed": true,
    "github_reviewed_at": "2020-06-16T21:30:11Z"
}
References

Affected packages

RubyGems / cocaine

Package

Name
cocaine
Purl
pkg:gem/cocaine

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0.4.0
Fixed
0.5.3

Affected versions

0.*

0.4.0
0.4.1
0.4.2
0.5.0
0.5.1
0.5.2