GHSA-rg32-m3hf-772v
Dashboard / Vulnerabilities / GHSA-rg32-m3hf-772v
Summary: Slanger Arbitrary command execution
Details: Slanger 0.6.0 is affected by Remote Code Execution (RCE). The impact is A remote attacker can execute arbitrary commands by sending a crafted request to the server. The component is Message handler & request validator. The attack vector is Remote unauthenticated. The fixed version is after commit 5267b455caeb2e055cccf0d2b6a22727c111f5c3.
References: https://nvd.nist.gov/vuln/detail/CVE-2019-1010306, https://github.com/stevegraham/slanger/pull/238, https://github.com/stevegraham/slanger/pull/238/commits/5267b455caeb2e055cccf0d2b6a22727c111f5c3, https://github.com/rubysec/ruby-advisory-db/blob/master/gems/slanger/CVE-2019-1010306.yml, https://github.com/stevegraham/slanger
Affected packages
Package
Name: slanger
Purl: pkg:gem/slanger
Affected ranges
Type: ECOSYSTEM
Events:
