RubySec

Providing security resources for the Ruby community

CVE-2023-28102 (discordrb): GHSL-2022-094: Remote Code Execution in discordrb

ADVISORIES

GEM

discordrb

SEVERITY

CVSS v3.x: 9.6 (Critical)

PATCHED VERSIONS

  • >= 3.4.3

DESCRIPTION

The encode_file method may lead to remote code execution (RCE) if invoked with untrusted user-controlled data.

RELATED