CVE-2013-6421: Command injection vulnerability
(updated )
The unpack_zip
function in archive_unpacker.rb
in the sprout gem for Ruby allows context-dependent attackers to execute arbitrary commands via shell metacharacters in a filename or path.
References
Detect and mitigate CVE-2013-6421 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →