CVE-2019-8323: Debian Linux

High severity, CVSS 7.5. EPSS: 3.3% chance of exploitation in the next 30 days.

An issue was discovered in RubyGems 2.6 and later through 3.0.2. Gem::GemcutterUtilities#with_response may output the API response to stdout as it is. Therefore, if the API side modifies the response, escape sequence injection may occur.

Affected products

  • Debian Debian Linux: version 9.0 only
  • Opensuse Leap: version 15.0 only; version 15.1 only
  • Rubygems Rubygems: from 2.6.0, up to and including 3.0.2

Published 2019-06-17. Last modified 2026-06-17.