Description
An issue was discovered in RubyGems 2.6 and later through 3.0.2. The gem owner command outputs the contents of the API response directly to stdout. Therefore, if the response is crafted, escape sequence injection may occur.
Remediation
References
Related Vulnerabilities
Atlassian Jira Incorrect Authorization Vulnerability (CVE-2019-3403)
Oracle JRE CVE-2017-10281 Vulnerability (CVE-2017-10281)
WordPress Plugin Arigato Autoresponder and Newsletter Cross-Site Scripting (2.7.1.1)
Oracle Database Server CVE-2012-1746 Vulnerability (CVE-2012-1746)
WordPress Plugin Verve Meta Boxes TimThumb Arbitrary File Upload (1.2.8)