CRITICAL 9.8 RubyGems
Command Injection in sequenceserver
GHSA-qv32-5wm2-p32h · CVE-2024-42360
Published · Modified
Description
Impact
Several HTTP endpoints did not properly sanitize user input and/or query parameters. This could be exploited to inject and run unwanted shell commands
Patches
Fixed in 3.1.2
Workarounds
No known workarounds
References
- WEB https://github.com/wurmlab/sequenceserver/security/advisories/GHSA-qv32-5wm2-p32h
- ADVISORY https://nvd.nist.gov/vuln/detail/CVE-2024-42360
- WEB https://github.com/wurmlab/sequenceserver/commit/457e52709f7f9ed2fceed59b3db564cb50785dba
- WEB https://github.com/rubysec/ruby-advisory-db/blob/master/gems/sequenceserver/CVE-2024-42360.yml
- PACKAGE https://github.com/wurmlab/sequenceserver
Ready to move
Start Securing
Free, no credit card | First findings in minutes