ruby: Code injection via command argument of Shell#test / Shell#[]
Published Nov 26, 2019
8.1
HIGHCVSS 3.1
EPSS 4.19%
Description
Ruby through 2.4.7, 2.5.x through 2.5.6, and 2.6.x through 2.6.4 allows code injection if the first argument (aka the "command" argument) to Shell#[] or Shell#test in lib/shell.rb is untrusted data. An attacker can exploit this to call an arbitrary Ruby method.
Affected products
No data.
Configuration 1
Configuration 2
- 8.0
- 9.0
No data.
Red Hat Enterprise Linux 8
ruby:2.5-8040020200923213910.522a0ee4
Fixed · RHSA-2021:2587
Red Hat Enterprise Linux 8
ruby:2.6-8040020210430142949.522a0ee4
Fixed · RHSA-2021:2588
Red Hat Enterprise Linux 8.1 Update Services for SAP Solutions
ruby:2.6-8010020220201152941.c27ad7f8
Fixed · RHSA-2022:0581
Red Hat Enterprise Linux 8.2 Extended Update Support
ruby:2.6-8020020220201131207.4cda2c84
Fixed · RHSA-2022:0582
Red Hat Software Collections for Red Hat Enterprise Linux 7
rh-ruby25-ruby-0:2.5.9-9.el7
Fixed · RHSA-2021:2104
Red Hat Software Collections for Red Hat Enterprise Linux 7
rh-ruby26-ruby-0:2.6.7-119.el7
Fixed · RHSA-2021:2230
Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUS
rh-ruby25-ruby-0:2.5.9-9.el7
Fixed · RHSA-2021:2104
Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUS
rh-ruby25-ruby-0:2.5.9-9.el7
Fixed · RHSA-2021:2104
Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUS
rh-ruby26-ruby-0:2.6.7-119.el7
Fixed · RHSA-2021:2230
Red Hat 3scale API Management Platform 2
3amp-system
Will not fix
Red Hat Enterprise Linux 5
ruby
Out of support scope
Red Hat Enterprise Linux 6
ruby
Out of support scope
Red Hat Enterprise Linux 7
ruby
Will not fix
Red Hat Software Collections
rh-ruby24-ruby
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 8 | ruby:2.5-8040020200923213910.522a0ee4 | Fixed | RHSA-2021:2587 |
| Red Hat Enterprise Linux 8 | ruby:2.6-8040020210430142949.522a0ee4 | Fixed | RHSA-2021:2588 |
| Red Hat Enterprise Linux 8.1 Update Services for SAP Solutions | ruby:2.6-8010020220201152941.c27ad7f8 | Fixed | RHSA-2022:0581 |
| Red Hat Enterprise Linux 8.2 Extended Update Support | ruby:2.6-8020020220201131207.4cda2c84 | Fixed | RHSA-2022:0582 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7 | rh-ruby25-ruby-0:2.5.9-9.el7 | Fixed | RHSA-2021:2104 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7 | rh-ruby26-ruby-0:2.6.7-119.el7 | Fixed | RHSA-2021:2230 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUS | rh-ruby25-ruby-0:2.5.9-9.el7 | Fixed | RHSA-2021:2104 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUS | rh-ruby25-ruby-0:2.5.9-9.el7 | Fixed | RHSA-2021:2104 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUS | rh-ruby26-ruby-0:2.6.7-119.el7 | Fixed | RHSA-2021:2230 |
| Red Hat 3scale API Management Platform 2 | 3amp-system | Will not fix | n/a |
| Red Hat Enterprise Linux 5 | ruby | Out of support scope | n/a |
| Red Hat Enterprise Linux 6 | ruby | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | ruby | Will not fix | n/a |
| Red Hat Software Collections | rh-ruby24-ruby | Will not fix | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (19)
- http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00041.html vendor-advisoryThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2019-16255 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1793683 Issue Tracking
- https://hackerone.com/reports/327512 ExploitPatchThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2019/11/msg00025.html Mailing ListThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2019/12/msg00009.html mailing-listMailing ListThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2020/08/msg00027.html mailing-listMailing ListThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2023/04/msg00033.html mailing-list
- https://nvd.nist.gov/vuln/detail/CVE-2019-16255
- https://seclists.org/bugtraq/2019/Dec/31 mailing-listBroken LinkMailing ListThird Party Advisory
- https://seclists.org/bugtraq/2019/Dec/32 mailing-listBroken LinkMailing ListThird Party Advisory
- https://security.gentoo.org/glsa/202003-06 vendor-advisoryThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2019-16255
- https://www.debian.org/security/2019/dsa-4587 vendor-advisoryThird Party Advisory
- https://www.oracle.com/security-alerts/cpujan2020.html PatchThird Party Advisory
- https://www.ruby-lang.org/ja/news/2019/10/01/code-injection-shell-test-cve-2019-16255/ Vendor Advisory
- https://www.ruby-lang.org/ja/news/2019/10/01/ruby-2-4-8-released/ Release Notes
- https://www.ruby-lang.org/ja/news/2019/10/01/ruby-2-5-7-released/ Release Notes
- https://www.ruby-lang.org/ja/news/2019/10/01/ruby-2-6-5-released/ Release Notes
Change history (0)
No recorded changes yet.