CVE-2019-8323: Debian Linux
High severity, CVSS 7.5. EPSS: 3.3% chance of exploitation in the next 30 days.
An issue was discovered in RubyGems 2.6 and later through 3.0.2. Gem::GemcutterUtilities#with_response may output the API response to stdout as it is. Therefore, if the API side modifies the response, escape sequence injection may occur.
Affected products
- Debian Debian Linux: version 9.0 only
- Opensuse Leap: version 15.0 only; version 15.1 only
- Rubygems Rubygems: from 2.6.0, up to and including 3.0.2
Published 2019-06-17. Last modified 2026-06-17.