CVE-2019-16255

HIGH

Ruby <2.4.7, 2.5.x<2.5.6, 2.6.x<2.6.4 - Code Injection

Title source: llm
STIX 2.1

Description

Ruby through 2.4.7, 2.5.x through 2.5.6, and 2.6.x through 2.6.4 allows code injection if the first argument (aka the "command" argument) to Shell#[] or Shell#test in lib/shell.rb is untrusted data. An attacker can exploit this to call an arbitrary Ruby method.

Scores

CVSS v3 8.1
EPSS 0.0116
EPSS Percentile 78.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-94
Status published
Products (5)
debian/debian_linux 8.0
debian/debian_linux 9.0
opensuse/leap 15.1
oracle/graalvm 19.3.0.2
ruby-lang/ruby 2.4.0 - 2.4.7
Published Nov 26, 2019
Tracked Since Feb 18, 2026