Launch Week Day 1: Announcing Security Design Review
CRITICAL 9.8 RubyGems

Command Injection in sequenceserver

GHSA-qv32-5wm2-p32h · CVE-2024-42360

Published · Modified

Description

Impact

Several HTTP endpoints did not properly sanitize user input and/or query parameters. This could be exploited to inject and run unwanted shell commands

Patches

Fixed in 3.1.2

Workarounds

No known workarounds

Ready to move

Start Securing

Free, no credit card | First findings in minutes