← All CVEs

CVE-2017-10784

high · 8.8

The Basic authentication code in WEBrick library in Ruby before 2.2.8, 2.3.x before 2.3.5, and 2.4.x through 2.4.1 allows remote attackers to inject terminal emulator escape sequences into its log and possibly execute arbitrary commands via a crafted user name.

8.8
CVSS
16.4%
EPSS (exploit prob.)
97th
EPSS percentile
2017-09-19
Published

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Weaknesses

CWE-287

Affected products

VendorProductAffected versions
ruby-langruby<= 2.2.7
ruby-langruby2.3.0
ruby-langruby2.3.0
ruby-langruby2.3.0
ruby-langruby2.3.1
ruby-langruby2.3.2
ruby-langruby2.3.3
ruby-langruby2.3.4
ruby-langruby2.4.0
ruby-langruby2.4.0
ruby-langruby2.4.0
ruby-langruby2.4.0
ruby-langruby2.4.0
ruby-langruby2.4.1

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2017-10784