suse · CVE-2019-8322

Quick triage

Priority: medium Published: 2021-05-30 14:24:36 UTC Updated: 2026-04-17 15:04:49 UTC

View at Official suse advisory, NVD, CVE.org · CVE detail

Freshness: upstream tracker timestamp is available; use API updated time as primary recency signal.

Tracker summary

CVE-2019-8322 severity moderate: SUSE including 332 source package names (2.17-17.3:libruby2_5-2_5-2.5.5-4.3.1, 2.17-17.3:ruby2.5-2.5.5-4.3.1, …), 1033 product×package rows across 247 product lines (Container bci/ruby, Container suse/rmt-server, … (247 product lines)): Fixed 874, Known Affected 157, Known Not Affected 2.

Description:

An issue was discovered in RubyGems 2.6 and later through 3.0.2. The gem owner command outputs the contents of the API response directly to stdout. Therefore, if the response is crafted, escape sequence injection may occur.

cvelogic Threat Intelligence