{"id":"GHSA-f489-655r-x6gr","summary":"smalruby and smalruby-editor vulnerable to OS Command Injection","details":"smalruby-editor prior to 0.4.1 and smalruby prior to 0.1.11 allows remote attackers to execute arbitrary OS commands via unspecified vectors.","aliases":["CVE-2017-2096"],"modified":"2023-11-01T04:48:07.202744Z","published":"2022-05-13T01:16:27Z","database_specific":{"severity":"CRITICAL","github_reviewed":true,"github_reviewed_at":"2023-01-27T00:00:58Z","nvd_published_at":"2017-04-28T16:59:00Z","cwe_ids":["CWE-78"]},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2017-2096"},{"type":"WEB","url":"https://github.com/rubysec/ruby-advisory-db/blob/master/gems/smalruby/CVE-2017-2096.yml"},{"type":"PACKAGE","url":"https://github.com/smalruby/smalruby-editor"},{"type":"WEB","url":"https://web.archive.org/web/20200227194312/http://www.securityfocus.com/bid/95775"},{"type":"WEB","url":"http://jvn.jp/en/jp/JVN50197114/index.html"},{"type":"WEB","url":"http://smalruby.jp/blog/2017/01/14/smalruby-editor-0-4-1-has-been-released-english.html"}],"affected":[{"package":{"name":"smalruby-editor","ecosystem":"RubyGems","purl":"pkg:gem/smalruby-editor"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.4.1"}]}],"versions":["0.0.1","0.0.10","0.0.11","0.0.12","0.0.2","0.0.3","0.0.4","0.0.5","0.0.6","0.0.7","0.0.8","0.0.9","0.1.0","0.1.1","0.1.10","0.1.11","0.1.12","0.1.13","0.1.14","0.1.15","0.1.16","0.1.17","0.1.18","0.1.19","0.1.2","0.1.20","0.1.21","0.1.22","0.1.23","0.1.24","0.1.3","0.1.4","0.1.5","0.1.6","0.1.7","0.1.8","0.1.9","0.2.0","0.2.1","0.2.2","0.2.3","0.2.4","0.2.5","0.2.6","0.2.7","0.3.0","0.3.1","0.3.2","0.3.3","0.3.4","0.3.5","0.4.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-f489-655r-x6gr/GHSA-f489-655r-x6gr.json"}},{"package":{"name":"smalruby","ecosystem":"RubyGems","purl":"pkg:gem/smalruby"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.1.11"}]}],"versions":["0.0.1","0.0.10","0.0.11","0.0.12","0.0.13","0.0.14","0.0.15","0.0.16","0.0.17","0.0.18","0.0.19","0.0.2","0.0.20","0.0.21","0.0.22","0.0.23","0.0.24","0.0.25","0.0.26","0.0.27","0.0.28","0.0.29","0.0.3","0.0.30","0.0.31","0.0.32","0.0.4","0.0.5","0.0.6","0.0.7","0.0.8","0.0.9","0.1.0","0.1.1","0.1.10","0.1.2","0.1.3","0.1.4","0.1.5","0.1.6","0.1.7","0.1.8","0.1.9"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-f489-655r-x6gr/GHSA-f489-655r-x6gr.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}