Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The Basic authentication code in WEBrick library in Ruby before 2.2.8, 2.3.x before 2.3.5, and 2.4.x through 2.4.1 allows remote attackers to inject terminal emulator escape sequences into its log and possibly execute arbitrary commands via a crafted user name.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Ruby 安全漏洞
Vulnerability Description
Ruby是日本软件开发者松本行弘所研发的一种跨平台、面向对象的动态类型编程语言。 Ruby 2.2.8之前的版本、2.3.5之前的2.3.x版本和2.4.x版本至2.4.1版本中的WEBrick库的Basic身份验证代码存在安全漏洞。远程攻击者可借助特制的用户名利用该漏洞向日志中注入终端模拟器转义字符串,可能执行任意命令。
CVSS Information
N/A
Vulnerability Type
N/A