cve/2019/CVE-2019-8324.md
2024-05-26 14:27:05 +02:00

770 B

CVE-2019-8324

Description

An issue was discovered in RubyGems 2.6 and later through 3.0.2. A crafted gem with a multi-line name is not handled correctly. Therefore, an attacker could inject arbitrary code to the stub line of gemspec, which is eval-ed by code in ensure_loadable_spec during the preinstall check.

POC

Reference

No PoCs from references.

Github