Show plain JSON{"affected_release": [{"advisory": "RHSA-2019:1429", "cpe": "cpe:/a:redhat:cloudforms_managementengine:5.10::el7", "package": "cfme-0:5.10.5.1-1.el7cf", "product_name": "CloudForms Management Engine 5.10", "release_date": "2019-06-11T00:00:00Z"}, {"advisory": "RHSA-2019:1429", "cpe": "cpe:/a:redhat:cloudforms_managementengine:5.10::el7", "package": "cfme-amazon-smartstate-0:5.10.5.1-1.el7cf", "product_name": "CloudForms Management Engine 5.10", "release_date": "2019-06-11T00:00:00Z"}, {"advisory": "RHSA-2019:1429", "cpe": "cpe:/a:redhat:cloudforms_managementengine:5.10::el7", "package": "cfme-appliance-0:5.10.5.1-1.el7cf", "product_name": "CloudForms Management Engine 5.10", "release_date": "2019-06-11T00:00:00Z"}, {"advisory": "RHSA-2019:1429", "cpe": "cpe:/a:redhat:cloudforms_managementengine:5.10::el7", "package": "cfme-gemset-0:5.10.5.1-1.el7cf", "product_name": "CloudForms Management Engine 5.10", "release_date": "2019-06-11T00:00:00Z"}, {"advisory": "RHSA-2019:1429", "cpe": "cpe:/a:redhat:cloudforms_managementengine:5.10::el7", "package": "ruby-0:2.4.6-91.el7cf", "product_name": "CloudForms Management Engine 5.10", "release_date": "2019-06-11T00:00:00Z"}, {"advisory": "RHSA-2019:1235", "cpe": "cpe:/o:redhat:enterprise_linux:7", "package": "ruby-0:2.0.0.648-35.el7_6", "product_name": "Red Hat Enterprise Linux 7", "release_date": "2019-05-15T00:00:00Z"}, {"advisory": "RHSA-2020:2769", "cpe": "cpe:/o:redhat:rhel_aus:7.4", "package": "ruby-0:2.0.0.648-37.el7_4", "product_name": "Red Hat Enterprise Linux 7.4 Advanced Update Support", "release_date": "2020-06-30T00:00:00Z"}, {"advisory": "RHSA-2020:2769", "cpe": "cpe:/o:redhat:rhel_tus:7.4", "package": "ruby-0:2.0.0.648-37.el7_4", "product_name": "Red Hat Enterprise Linux 7.4 Telco Extended Update Support", "release_date": "2020-06-30T00:00:00Z"}, {"advisory": "RHSA-2020:2769", "cpe": "cpe:/o:redhat:rhel_e4s:7.4", "package": "ruby-0:2.0.0.648-37.el7_4", "product_name": "Red Hat Enterprise Linux 7.4 Update Services for SAP Solutions", "release_date": "2020-06-30T00:00:00Z"}, {"advisory": "RHSA-2019:1972", "cpe": "cpe:/a:redhat:enterprise_linux:8", "package": "ruby:2.5-8000020190524123348.55190bc5", "product_name": "Red Hat Enterprise Linux 8", "release_date": "2019-08-07T00:00:00Z"}, {"advisory": "RHSA-2019:1150", "cpe": "cpe:/a:redhat:rhel_software_collections:3::el6", "package": "rh-ruby24-ruby-0:2.4.6-92.el6", "product_name": "Red Hat Software Collections for Red Hat Enterprise Linux 6", "release_date": "2019-05-13T00:00:00Z"}, {"advisory": "RHSA-2019:1151", "cpe": "cpe:/a:redhat:rhel_software_collections:3::el6", "package": "rh-ruby23-ruby-0:2.3.8-70.el6", "product_name": "Red Hat Software Collections for Red Hat Enterprise Linux 6", "release_date": "2019-05-13T00:00:00Z"}, {"advisory": "RHSA-2019:1148", "cpe": "cpe:/a:redhat:rhel_software_collections:3::el7", "package": "rh-ruby25-ruby-0:2.5.5-7.el7", "product_name": "Red Hat Software Collections for Red Hat Enterprise Linux 7", "release_date": "2019-05-13T00:00:00Z"}, {"advisory": "RHSA-2019:1150", "cpe": "cpe:/a:redhat:rhel_software_collections:3::el7", "package": "rh-ruby24-ruby-0:2.4.6-92.el7", "product_name": "Red Hat Software Collections for Red Hat Enterprise Linux 7", "release_date": "2019-05-13T00:00:00Z"}, {"advisory": "RHSA-2019:1151", "cpe": "cpe:/a:redhat:rhel_software_collections:3::el7", "package": "rh-ruby23-ruby-0:2.3.8-70.el7", "product_name": "Red Hat Software Collections for Red Hat Enterprise Linux 7", "release_date": "2019-05-13T00:00:00Z"}, {"advisory": "RHSA-2019:1148", "cpe": "cpe:/a:redhat:rhel_software_collections:3::el7", "package": "rh-ruby25-ruby-0:2.5.5-7.el7", "product_name": "Red Hat Software Collections for Red Hat Enterprise Linux 7.4 EUS", "release_date": "2019-05-13T00:00:00Z"}, {"advisory": "RHSA-2019:1150", "cpe": "cpe:/a:redhat:rhel_software_collections:3::el7", "package": "rh-ruby24-ruby-0:2.4.6-92.el7", "product_name": "Red Hat Software Collections for Red Hat Enterprise Linux 7.4 EUS", "release_date": "2019-05-13T00:00:00Z"}, {"advisory": "RHSA-2019:1151", "cpe": "cpe:/a:redhat:rhel_software_collections:3::el7", "package": "rh-ruby23-ruby-0:2.3.8-70.el7", "product_name": "Red Hat Software Collections for Red Hat Enterprise Linux 7.4 EUS", "release_date": "2019-05-13T00:00:00Z"}, {"advisory": "RHSA-2019:1148", "cpe": "cpe:/a:redhat:rhel_software_collections:3::el7", "package": "rh-ruby25-ruby-0:2.5.5-7.el7", "product_name": "Red Hat Software Collections for Red Hat Enterprise Linux 7.5 EUS", "release_date": "2019-05-13T00:00:00Z"}, {"advisory": "RHSA-2019:1150", "cpe": "cpe:/a:redhat:rhel_software_collections:3::el7", "package": "rh-ruby24-ruby-0:2.4.6-92.el7", "product_name": "Red Hat Software Collections for Red Hat Enterprise Linux 7.5 EUS", "release_date": "2019-05-13T00:00:00Z"}, {"advisory": "RHSA-2019:1151", "cpe": "cpe:/a:redhat:rhel_software_collections:3::el7", "package": "rh-ruby23-ruby-0:2.3.8-70.el7", "product_name": "Red Hat Software Collections for Red Hat Enterprise Linux 7.5 EUS", "release_date": "2019-05-13T00:00:00Z"}, {"advisory": "RHSA-2019:1148", "cpe": "cpe:/a:redhat:rhel_software_collections:3::el7", "package": "rh-ruby25-ruby-0:2.5.5-7.el7", "product_name": "Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUS", "release_date": "2019-05-13T00:00:00Z"}, {"advisory": "RHSA-2019:1150", "cpe": "cpe:/a:redhat:rhel_software_collections:3::el7", "package": "rh-ruby24-ruby-0:2.4.6-92.el7", "product_name": "Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUS", "release_date": "2019-05-13T00:00:00Z"}, {"advisory": "RHSA-2019:1151", "cpe": "cpe:/a:redhat:rhel_software_collections:3::el7", "package": "rh-ruby23-ruby-0:2.3.8-70.el7", "product_name": "Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUS", "release_date": "2019-05-13T00:00:00Z"}], "bugzilla": {"description": "rubygems: Installing a malicious gem may lead to arbitrary code execution", "id": "1692520", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1692520"}, "csaw": false, "cvss3": {"cvss3_base_score": "7.2", "cvss3_scoring_vector": "CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H", "status": "verified"}, "cwe": "CWE-20", "details": ["An issue was discovered in RubyGems 2.6 and later through 3.0.2. A crafted gem with a multi-line name is not handled correctly. Therefore, an attacker could inject arbitrary code to the stub line of gemspec, which is eval-ed by code in ensure_loadable_spec during the preinstall check.", "A flaw was found in RubyGems. A crafted gem with a multi-line name is not handled correctly allowing an attacker to inject arbitrary code to the stub line of gemspec. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability."], "name": "CVE-2019-8324", "package_state": [{"cpe": "cpe:/o:redhat:enterprise_linux:6", "fix_state": "Not affected", "package_name": "rubygems", "product_name": "Red Hat Enterprise Linux 6"}, {"cpe": "cpe:/a:redhat:rhel_software_collections:3", "fix_state": "Not affected", "package_name": "rh-ruby26-ruby", "product_name": "Red Hat Software Collections"}], "public_date": "2019-03-05T00:00:00Z", "references": ["https://www.cve.org/CVERecord?id=CVE-2019-8324\nhttps://nvd.nist.gov/vuln/detail/CVE-2019-8324\nhttps://blog.rubygems.org/2019/03/05/security-advisories-2019-03.html\nhttps://www.ruby-lang.org/en/news/2019/03/05/multiple-vulnerabilities-in-rubygems/"], "threat_severity": "Important"}