CVE-2013-2090
The set_meta_data function in lib/cremefraiche.rb in the Creme Fraiche gem before 0.6.1 for Ruby allows remote attackers to execute arbitrary commands via shell metacharacters in the file name of an email attachment.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (4.25%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The set_meta_data function in lib/cremefraiche.rb in the Creme Fraiche gem before 0.6.1 for Ruby allows remote attackers to execute arbitrary commands via shell metacharacters in the file name of an email attachment. NOTE: some of these details are obtained from third party information.
- CVSS 2.0
- 9.3 HIGHAV:N/AC:M/Au:N/C:C/I:C/A:C
- EPSS
- 4.25% probability · 90th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-78
- Affected
- uplawski/creme fraiche
- Source
- secalert@redhat.com
References
- http://osvdb.org/93395
- http://packetstormsecurity.com/files/121635/Ruby-Gem-Creme-Fraiche-0.6-Command-Injection.htmlExploit
- http://secunia.com/advisories/53391
- http://www.vapid.dhs.org/advisories/cremefraiche-cmd-inj.htmlExploit
- https://exchange.xforce.ibmcloud.com/vulnerabilities/84271
- http://osvdb.org/93395
- http://packetstormsecurity.com/files/121635/Ruby-Gem-Creme-Fraiche-0.6-Command-Injection.htmlExploit
- http://secunia.com/advisories/53391
- http://www.vapid.dhs.org/advisories/cremefraiche-cmd-inj.htmlExploit
- https://exchange.xforce.ibmcloud.com/vulnerabilities/84271
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.