colorscore Command Injection vulnerability
Critical severity
GitHub Reviewed
Published
Oct 24, 2017
to the GitHub Advisory Database
•
Updated Aug 29, 2023
Description
Published to the GitHub Advisory Database
Oct 24, 2017
Reviewed
Jun 16, 2020
Last updated
Aug 29, 2023
The initialize method in the Histogram class in
lib/colorscore/histogram.rb
in the colorscore gem before 0.0.5 for Ruby allows context-dependent attackers to execute arbitrary code via shell metacharacters in the (1)image_path
, (2)colors
, or (3)depth
variable.References