Description
An issue was discovered in RubyGems 2.6 and later through 3.0.2. Since Gem::CommandManager#run calls alert_error without escaping, escape sequence injection is possible. (There are many ways to cause an error.)
Remediation
References
Related Vulnerabilities
WordPress Plugin Import and export users and customers CSV Injection (1.16.3.5)
WordPress Plugin TweetScribe Cross-Site Request Forgery (1.1)
Moodle Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2016-2154)
WordPress Plugin Grid Gallery-Photo Image Grid Gallery Cross-Site Scripting (1.2.4)