Description
An issue was discovered in RubyGems 2.6 and later through 3.0.2. Gem::GemcutterUtilities#with_response may output the API response to stdout as it is. Therefore, if the API side modifies the response, escape sequence injection may occur.
Remediation
References
Related Vulnerabilities
OpenSSL Improper Input Validation Vulnerability (CVE-2016-6302)
PostgreSQL Improper Validation of Specified Type of Input Vulnerability (CVE-2026-2003)
WordPress Plugin SportsPress-Sports Club & League Manager Cross-Site Scripting (2.7.1)
WordPress Plugin MAZ Loader-Preloader Builder for WordPress SQL Injection (1.3.2)