Description
An issue was discovered in RubyGems 2.6 and later through 3.0.2. Since Gem::CommandManager#run calls alert_error without escaping, escape sequence injection is possible. (There are many ways to cause an error.)
Remediation
References
Related Vulnerabilities
Jboss EAP CVE-2012-4529 Vulnerability (CVE-2012-4529)
WordPress Plugin qTranslate Cross-Site Scripting (2.5.39)
WordPress Plugin CMS Commander Client PHP Object Injection (2.21)
Joomla! Core 3.x.x Security Bypass (3.0.0 - 3.4.4)
WordPress Plugin Better WordPress Minify Arbitrary File Disclosure (1.2.2)