peter bassill · operator
$ cve CVE-2017-0899 JSON

CVE-2017-0899

9.8
CRITICAL · CVSS 3.0 · EPSS 11.1% (pctl 96)

Patch early

EPSS 11.1% — above the 10% action threshold.

Description

RubyGems version 2.6.12 and earlier is vulnerable to maliciously crafted gem specifications that include terminal escape characters. Printing the gem specification would execute terminal escape sequences.

Scoring

CVSS9.8 (CRITICAL, v3.0)
VectorCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS11.1% — more likely to be exploited than 96% of all CVEs
WeaknessCWE-150
On CISA KEVno
Public exploitnone known
Published2017-08-31
Last modified2026-06-17

Affected (8)

VendorProduct
debiandebian linux
redhatenterprise linux desktop
redhatenterprise linux server
redhatenterprise linux server aus
redhatenterprise linux server eus
redhatenterprise linux server tus
redhatenterprise linux workstation
rubygemsrubygems

References

→ the Explorer  ·  watch your stack  ·  NVD