smalruby and smalruby-editor vulnerable to OS Command Injection
Critical severity
GitHub Reviewed
Published
May 13, 2022
to the GitHub Advisory Database
•
Updated Mar 6, 2023
Description
Published by the National Vulnerability Database
Apr 28, 2017
Published to the GitHub Advisory Database
May 13, 2022
Reviewed
Jan 27, 2023
Last updated
Mar 6, 2023
smalruby-editor prior to 0.4.1 and smalruby prior to 0.1.11 allows remote attackers to execute arbitrary OS commands via unspecified vectors.
References