GHSA-vm28-mrm7-fpjq
HIGHCVE-2014-2888lib/sfpagent/bsig.rb in the sfpagent gem before 0.4.15 for Ruby allows remote attackers to execute arbitrary commands via shell metacharacters in the module name in a JSON request.
- Affected
- < 0.4.15
- Fixed in
- 0.4.15
- Weakness
- CWE-77
- Published
- 2017-10-24
- Source
- github