Skip to content

Curl Gem insufficient URL escaping command injection

High severity GitHub Reviewed Published Oct 24, 2017 to the GitHub Advisory Database • Updated Aug 29, 2023

Package

bundler curl (RubyGems)

Affected versions

<= 0.0.9

Patched versions

None
Published to the GitHub Advisory Database Oct 24, 2017
Reviewed Jun 16, 2020
Last updated Aug 29, 2023

Severity

High

EPSS score

0.815%
(82nd percentile)

Weaknesses

CVE ID

CVE-2013-2617

GHSA ID

GHSA-hxx6-p24v-wg8c

Source code

Loading Checking history
See something to contribute? Suggest improvements for this vulnerability.