{"schema_version":"1.7.3","id":"GHSA-jppv-gw3r-w3q8","published":"2020-02-28T16:54:36Z","modified":"2024-02-19T05:32:17.994147Z","aliases":["CVE-2020-8130"],"summary":"OS Command Injection in Rake","details":"There is an OS command injection vulnerability in Ruby Rake before 12.3.3 in `Rake::FileList` when supplying a filename that begins with the pipe character `|`.","affected":[{"package":{"name":"rake","ecosystem":"RubyGems","purl":"pkg:gem/rake"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"12.3.3"}]}],"versions":["0.4.10","0.4.11","0.4.12","0.4.13","0.4.14","0.4.15","0.4.8","0.4.9","0.5.0","0.5.3","0.5.4","0.6.0","0.6.2","0.7.0","0.7.1","0.7.2","0.7.3","0.8.0","0.8.1","0.8.2","0.8.3","0.8.4","0.8.5","0.8.6","0.8.7","0.9.0","0.9.0.beta.0","0.9.0.beta.1","0.9.0.beta.2","0.9.0.beta.4","0.9.0.beta.5","0.9.1","0.9.2","0.9.2.2","0.9.3","0.9.3.beta.1","0.9.3.beta.2","0.9.3.beta.3","0.9.3.beta.4","0.9.4","0.9.5","0.9.6","10.0.0","10.0.0.beta.1","10.0.0.beta.2","10.0.1","10.0.2","10.0.3","10.0.4","10.1.0","10.1.0.beta.1","10.1.0.beta.2","10.1.0.beta.3","10.1.1","10.2.0","10.2.1","10.2.2","10.3.0","10.3.1","10.3.2","10.4.0","10.4.1","10.4.2","10.5.0","11.0.1","11.1.0","11.1.1","11.1.2","11.2.0","11.2.2","11.3.0","12.0.0","12.0.0.beta1","12.1.0","12.2.0","12.2.1","12.3.0","12.3.1","12.3.2"],"database_specific":{"last_known_affected_version_range":"<= 12.3.2","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/02/GHSA-jppv-gw3r-w3q8/GHSA-jppv-gw3r-w3q8.json"}}],"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2020-8130"},{"type":"WEB","url":"https://github.com/ruby/rake/commit/5b8f8fc41a5d7d7d6a5d767e48464c60884d3aee"},{"type":"WEB","url":"https://hackerone.com/reports/651518"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-jppv-gw3r-w3q8"},{"type":"PACKAGE","url":"https://github.com/ruby/rake"},{"type":"WEB","url":"https://github.com/rubysec/ruby-advisory-db/blob/master/gems/rake/CVE-2020-8130.yml"},{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2020/02/msg00026.html"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/523CLQ62VRN3VVC52KMPTROCCKY4Z36B"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/VXMX4ARNX2JLRJMSH4N3J3UBMUT5CI44"},{"type":"WEB","url":"https://usn.ubuntu.com/4295-1"},{"type":"WEB","url":"http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00041.html"}],"database_specific":{"cwe_ids":["CWE-78"],"github_reviewed":true,"github_reviewed_at":"2020-02-25T15:50:03Z","nvd_published_at":null,"severity":"MODERATE"},"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H"}]}