There is an OS command injection vulnerability in Ruby Rake < 12.3.3 in Rake::FileList when supplying a filename that begins with the pipe character `|`.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: hackerone

Published: 2020-02-24T14:41:26

Updated: 2020-04-27T06:06:07

Reserved: 2020-01-28T00:00:00


Link: CVE-2020-8130

JSON object: View

cve-icon NVD Information

Status : Modified

Published: 2020-02-24T15:15:11.957

Modified: 2023-11-07T03:26:16.500


Link: CVE-2020-8130

JSON object: View

cve-icon Redhat Information

No data.

CWE