Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 710980 (CVE-2020-8130) - <dev-ruby/rake-12.3.3: command injection vulnerability (CVE-2020-8130)
Summary: <dev-ruby/rake-12.3.3: command injection vulnerability (CVE-2020-8130)
Status: RESOLVED FIXED
Alias: CVE-2020-8130
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal normal (vote)
Assignee: Gentoo Security
URL: https://hackerone.com/reports/651518
Whiteboard: B2 [noglsa cve]
Keywords:
Depends on:
Blocks:
 
Reported: 2020-02-27 18:25 UTC by Thomas Deutschmann
Modified: 2020-04-10 23:11 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Thomas Deutschmann gentoo-dev Security 2020-02-27 18:25:20 UTC
There is an OS command injection vulnerability in Ruby Rake < 12.3.3 in Rake::FileList when supplying a filename that begins with the pipe character `|`.

Upstream patch:

https://github.com/ruby/rake/commit/5b8f8fc41a5d7d7d6a5d767e48464c60884d3aee
Comment 1 Thomas Deutschmann gentoo-dev Security 2020-02-27 18:27:16 UTC
GLSA vote: Note!

Repository is clean, all done.