OS Command Injection in Rake
Moderate severity
GitHub Reviewed
Published
Feb 28, 2020
to the GitHub Advisory Database
•
Updated Aug 29, 2023
Description
Reviewed
Feb 25, 2020
Published to the GitHub Advisory Database
Feb 28, 2020
Last updated
Aug 29, 2023
There is an OS command injection vulnerability in Ruby Rake before 12.3.3 in
Rake::FileList
when supplying a filename that begins with the pipe character|
.References