CVE-2017-17790: Ruby-Lang Ruby
Critical severity, CVSS 9.8. EPSS: 5.9% chance of exploitation in the next 30 days.
The lazy_initialize function in lib/resolv.rb in Ruby through 2.4.3 uses Kernel#open, which might allow Command Injection attacks, as demonstrated by a Resolv::Hosts::new argument beginning with a '|' character, a different vulnerability than CVE-2017-17405. NOTE: situations with untrusted input may be highly unlikely.
Affected products
- Ruby-Lang Ruby: from 2.2, up to and including 2.2.8; from 2.3, up to and including 2.3.5; from 2.4, up to and including 2.4.2; version 2.5.0 only
Published 2017-12-20. Last modified 2026-06-17.