Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2019-16255

Ruby through 2.4.7, 2.5.x through 2.5.6, and 2.6.x through 2.6.4 allows code injection if the first argument (aka the "command" argument) to Shell#[] or Shell#test in lib/shell.rb is untrusted data. An attacker can exploit this to call an arbitrary Ruby method.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.016
EPSS Ranking 81.0%
CVSS Severity
CVSS v3 Score 8.1
CVSS v2 Score 6.8
References
Products affected by CVE-2019-16255
  • Oracle » Graalvm » Version: 19.3.0.2
    cpe:2.3:a:oracle:graalvm:19.3.0.2
  • Ruby-Lang » Ruby » Version: 2.4.0
    cpe:2.3:a:ruby-lang:ruby:2.4.0
  • Ruby-Lang » Ruby » Version: 2.4.1
    cpe:2.3:a:ruby-lang:ruby:2.4.1
  • Ruby-Lang » Ruby » Version: 2.4.2
    cpe:2.3:a:ruby-lang:ruby:2.4.2
  • Ruby-Lang » Ruby » Version: 2.4.3
    cpe:2.3:a:ruby-lang:ruby:2.4.3
  • Ruby-Lang » Ruby » Version: 2.4.4
    cpe:2.3:a:ruby-lang:ruby:2.4.4
  • Ruby-Lang » Ruby » Version: 2.4.5
    cpe:2.3:a:ruby-lang:ruby:2.4.5
  • Ruby-Lang » Ruby » Version: 2.4.6
    cpe:2.3:a:ruby-lang:ruby:2.4.6
  • Ruby-Lang » Ruby » Version: 2.4.7
    cpe:2.3:a:ruby-lang:ruby:2.4.7
  • Ruby-Lang » Ruby » Version: 2.5.0
    cpe:2.3:a:ruby-lang:ruby:2.5.0
  • Ruby-Lang » Ruby » Version: 2.5.1
    cpe:2.3:a:ruby-lang:ruby:2.5.1
  • Ruby-Lang » Ruby » Version: 2.5.2
    cpe:2.3:a:ruby-lang:ruby:2.5.2
  • Ruby-Lang » Ruby » Version: 2.5.3
    cpe:2.3:a:ruby-lang:ruby:2.5.3
  • Ruby-Lang » Ruby » Version: 2.5.4
    cpe:2.3:a:ruby-lang:ruby:2.5.4
  • Ruby-Lang » Ruby » Version: 2.5.5
    cpe:2.3:a:ruby-lang:ruby:2.5.5
  • Ruby-Lang » Ruby » Version: 2.5.6
    cpe:2.3:a:ruby-lang:ruby:2.5.6
  • Ruby-Lang » Ruby » Version: 2.6.0
    cpe:2.3:a:ruby-lang:ruby:2.6.0
  • Ruby-Lang » Ruby » Version: 2.6.1
    cpe:2.3:a:ruby-lang:ruby:2.6.1
  • Ruby-Lang » Ruby » Version: 2.6.2
    cpe:2.3:a:ruby-lang:ruby:2.6.2
  • Ruby-Lang » Ruby » Version: 2.6.3
    cpe:2.3:a:ruby-lang:ruby:2.6.3
  • Ruby-Lang » Ruby » Version: 2.6.4
    cpe:2.3:a:ruby-lang:ruby:2.6.4
  • Debian » Debian Linux » Version: 8.0
    cpe:2.3:o:debian:debian_linux:8.0
  • Debian » Debian Linux » Version: 9.0
    cpe:2.3:o:debian:debian_linux:9.0
  • Opensuse » Leap » Version: 15.1
    cpe:2.3:o:opensuse:leap:15.1


Contact Us

Shodan ® - All rights reserved