RubySec

Providing security resources for the Ruby community

CVE-2014-1834 (echor): echor Gem for Ruby backplane.rb perform_request Function Arbitrary Command Execution

ADVISORIES

GEM

echor

SEVERITY

CVSS v3.x: 7.8 (High)

PATCHED VERSIONS

None.

DESCRIPTION

Echor Gem for Ruby contains a flaw in backplane.rb in the perform_request function that is triggered when a semi-colon (;) is injected into a username or password. This may allow a context-dependent attacker to inject arbitrary commands if the gem is used in a rails application.