rubygems: Escape sequence injection vulnerability in API response handling
Published Jun 17, 2019
7.5
HIGHCVSS 3.1
EPSS 3.28%
Description
An issue was discovered in RubyGems 2.6 and later through 3.0.2. Gem::GemcutterUtilities#with_response may output the API response to stdout as it is. Therefore, if the API side modifies the response, escape sequence injection may occur.
Affected products
No data.
No data.
CloudForms Management Engine 5.10
cfme-0:5.10.5.1-1.el7cf
Fixed · RHSA-2019:1429
CloudForms Management Engine 5.10
cfme-amazon-smartstate-0:5.10.5.1-1.el7cf
Fixed · RHSA-2019:1429
CloudForms Management Engine 5.10
cfme-appliance-0:5.10.5.1-1.el7cf
Fixed · RHSA-2019:1429
CloudForms Management Engine 5.10
cfme-gemset-0:5.10.5.1-1.el7cf
Fixed · RHSA-2019:1429
CloudForms Management Engine 5.10
ruby-0:2.4.6-91.el7cf
Fixed · RHSA-2019:1429
Red Hat Enterprise Linux 7
ruby-0:2.0.0.648-35.el7_6
Fixed · RHSA-2019:1235
Red Hat Enterprise Linux 7.4 Advanced Update Support
ruby-0:2.0.0.648-37.el7_4
Fixed · RHSA-2020:2769
Red Hat Enterprise Linux 7.4 Telco Extended Update Support
ruby-0:2.0.0.648-37.el7_4
Fixed · RHSA-2020:2769
Red Hat Enterprise Linux 7.4 Update Services for SAP Solutions
ruby-0:2.0.0.648-37.el7_4
Fixed · RHSA-2020:2769
Red Hat Enterprise Linux 8
ruby:2.5-8010020190711131821.cdc1202b
Fixed · RHBA-2019:3384
Red Hat Software Collections for Red Hat Enterprise Linux 6
rh-ruby24-ruby-0:2.4.6-92.el6
Fixed · RHSA-2019:1150
Red Hat Software Collections for Red Hat Enterprise Linux 7
rh-ruby24-ruby-0:2.4.6-92.el7
Fixed · RHSA-2019:1150
Red Hat Software Collections for Red Hat Enterprise Linux 7
rh-ruby25-ruby-0:2.5.5-7.el7
Fixed · RHSA-2019:1148
Red Hat Software Collections for Red Hat Enterprise Linux 7.4 EUS
rh-ruby24-ruby-0:2.4.6-92.el7
Fixed · RHSA-2019:1150
Red Hat Software Collections for Red Hat Enterprise Linux 7.4 EUS
rh-ruby25-ruby-0:2.5.5-7.el7
Fixed · RHSA-2019:1148
Red Hat Software Collections for Red Hat Enterprise Linux 7.5 EUS
rh-ruby24-ruby-0:2.4.6-92.el7
Fixed · RHSA-2019:1150
Red Hat Software Collections for Red Hat Enterprise Linux 7.5 EUS
rh-ruby25-ruby-0:2.5.5-7.el7
Fixed · RHSA-2019:1148
Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUS
rh-ruby24-ruby-0:2.4.6-92.el7
Fixed · RHSA-2019:1150
Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUS
rh-ruby25-ruby-0:2.5.5-7.el7
Fixed · RHSA-2019:1148
Red Hat Enterprise Linux 6
rubygems
Will not fix
Red Hat Software Collections
rh-ruby23-ruby
Fix deferred
Red Hat Software Collections
rh-ruby26-ruby
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| CloudForms Management Engine 5.10 | cfme-0:5.10.5.1-1.el7cf | Fixed | RHSA-2019:1429 |
| CloudForms Management Engine 5.10 | cfme-amazon-smartstate-0:5.10.5.1-1.el7cf | Fixed | RHSA-2019:1429 |
| CloudForms Management Engine 5.10 | cfme-appliance-0:5.10.5.1-1.el7cf | Fixed | RHSA-2019:1429 |
| CloudForms Management Engine 5.10 | cfme-gemset-0:5.10.5.1-1.el7cf | Fixed | RHSA-2019:1429 |
| CloudForms Management Engine 5.10 | ruby-0:2.4.6-91.el7cf | Fixed | RHSA-2019:1429 |
| Red Hat Enterprise Linux 7 | ruby-0:2.0.0.648-35.el7_6 | Fixed | RHSA-2019:1235 |
| Red Hat Enterprise Linux 7.4 Advanced Update Support | ruby-0:2.0.0.648-37.el7_4 | Fixed | RHSA-2020:2769 |
| Red Hat Enterprise Linux 7.4 Telco Extended Update Support | ruby-0:2.0.0.648-37.el7_4 | Fixed | RHSA-2020:2769 |
| Red Hat Enterprise Linux 7.4 Update Services for SAP Solutions | ruby-0:2.0.0.648-37.el7_4 | Fixed | RHSA-2020:2769 |
| Red Hat Enterprise Linux 8 | ruby:2.5-8010020190711131821.cdc1202b | Fixed | RHBA-2019:3384 |
| Red Hat Software Collections for Red Hat Enterprise Linux 6 | rh-ruby24-ruby-0:2.4.6-92.el6 | Fixed | RHSA-2019:1150 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7 | rh-ruby24-ruby-0:2.4.6-92.el7 | Fixed | RHSA-2019:1150 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7 | rh-ruby25-ruby-0:2.5.5-7.el7 | Fixed | RHSA-2019:1148 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.4 EUS | rh-ruby24-ruby-0:2.4.6-92.el7 | Fixed | RHSA-2019:1150 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.4 EUS | rh-ruby25-ruby-0:2.5.5-7.el7 | Fixed | RHSA-2019:1148 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.5 EUS | rh-ruby24-ruby-0:2.4.6-92.el7 | Fixed | RHSA-2019:1150 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.5 EUS | rh-ruby25-ruby-0:2.5.5-7.el7 | Fixed | RHSA-2019:1148 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUS | rh-ruby24-ruby-0:2.4.6-92.el7 | Fixed | RHSA-2019:1150 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUS | rh-ruby25-ruby-0:2.5.5-7.el7 | Fixed | RHSA-2019:1148 |
| Red Hat Enterprise Linux 6 | rubygems | Will not fix | n/a |
| Red Hat Software Collections | rh-ruby23-ruby | Fix deferred | n/a |
| Red Hat Software Collections | rh-ruby26-ruby | Not affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
AV:N/AC:L/Au:N/C:N/I:P/A:N
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2021–2026- EPSS v1
- EPSS v5
- EPSS v2
- EPSS v3
Percentile over time
- EPSS v1
- EPSS v5
- EPSS v2
- EPSS v3
Table of values (14 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 3.28% (0.03281) | 88.03th | v5 (v2026.06.15) |
| Jun 15, 2026 | 3.37% (0.03372) | 87.16th | v5 (v2026.06.15) |
| Jul 20, 2024 | 0.20% (0.00201) | 58.56th | v3 (v2023.03.01) |
| Jun 10, 2024 | 0.20% (0.00201) | 58.20th | v3 (v2023.03.01) |
| Oct 11, 2023 | 0.15% (0.00147) | 50.38th | v3 (v2023.03.01) |
| Sep 3, 2023 | 0.21% (0.00209) | 58.17th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.18% (0.00180) | 53.40th | v3 (v2023.03.01) |
| Mar 6, 2023 | 0.95% (0.00954) | 36.37th | v2 (v2022.01.01) |
| Apr 1, 2022 | 0.95% (0.00954) | 32.50th | v2 (v2022.01.01) |
| Feb 4, 2022 | 5.74% (0.05736) | 77.22th | v2 (v2022.01.01) |
| Feb 3, 2022 | 3.63% (0.03630) | 71.73th | v5 (v2026.06.15) |
| Jan 6, 2022 | 3.63% (0.03630) | 71.48th | v1 |
| Sep 1, 2021 | 0.83% (0.00833) | 57.50th | v1 |
| Apr 14, 2021 | 0.83% (0.00833) | 0.00th | v1 |
References (10)
- http://lists.opensuse.org/opensuse-security-announce/2019-07/msg00036.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2019-8323 Vendor Advisory
- https://blog.rubygems.org/2019/03/05/security-advisories-2019-03.html
- https://bugzilla.redhat.com/show_bug.cgi?id=1692519 Issue Tracking
- https://github.com/advisories/GHSA-3h4r-pjv6-cph9 Advisory
- https://github.com/rubysec/ruby-advisory-db/blob/master/gems/rubygems-update/CVE-2019-8323.yml
- https://hackerone.com/reports/315081 x_refsource_MISCPermissions RequiredThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2020/08/msg00027.html mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2019-8323
- https://www.cve.org/CVERecord?id=CVE-2019-8323
| Link | Providers | Tags |
|---|---|---|
| http://lists.opensuse.org/opensuse-security-announce/2019-07/msg00036.html | vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory | |
| https://access.redhat.com/security/cve/CVE-2019-8323 | Vendor Advisory | |
| https://blog.rubygems.org/2019/03/05/security-advisories-2019-03.html | ||
| https://bugzilla.redhat.com/show_bug.cgi?id=1692519 | Issue Tracking | |
| https://github.com/advisories/GHSA-3h4r-pjv6-cph9 | Advisory | |
| https://github.com/rubysec/ruby-advisory-db/blob/master/gems/rubygems-update/CVE-2019-8323.yml | ||
| https://hackerone.com/reports/315081 | x_refsource_MISCPermissions RequiredThird Party Advisory | |
| https://lists.debian.org/debian-lts-announce/2020/08/msg00027.html | mailing-listx_refsource_MLISTMailing ListThird Party Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2019-8323 | ||
| https://www.cve.org/CVERecord?id=CVE-2019-8323 |
Change history (0)
No recorded changes yet.