RubySec

Providing security resources for the Ruby community

CVE-2024-42360 (sequenceserver): Command Injection in sequenceserver gem

ADVISORIES

GEM

sequenceserver

SEVERITY

CVSS v3.x: 9.8 (Critical)

PATCHED VERSIONS

  • >= 3.1.2

DESCRIPTION

Impact

Several HTTP endpoints did not properly sanitize user input and/or query parameters. This could be exploited to inject and run unwanted shell commands

Patches

Fixed in 3.1.2

Workarounds

No known workarounds

RELATED