Skip to content

Command Injection

Critical
yannickwurm published GHSA-qv32-5wm2-p32h Aug 13, 2024

Package

bundler sequenceserver (RubyGems)

Affected versions

< 3.1.2

Patched versions

3.1.2

Description

Impact

Several HTTP endpoints did not properly sanitize user input and/or query parameters. This could be exploited to inject and run unwanted shell commands

Patches

Fixed in 3.1.2

Workarounds

No known workarounds

Severity

Critical

CVE ID

CVE-2024-42360

Weaknesses

Credits