CVE-2019-8321: Debian Linux
High severity, CVSS 7.5. EPSS: 3.3% chance of exploitation in the next 30 days.
An issue was discovered in RubyGems 2.6 and later through 3.0.2. Since Gem::UserInteraction#verbose calls say without escaping, escape sequence injection is possible.
Affected products
- Debian Debian Linux: version 9.0 only
- Opensuse Leap: version 15.0 only; version 15.1 only
- Rubygems Rubygems: from 2.6.0, up to and including 3.0.2
Published 2019-06-17. Last modified 2026-06-17.