Arbitrary Command Execution Affecting webbynode package, versions >= 0


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
3.53% (88th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-RUBY-WEBBYNODE-20126
  • published11 Dec 2013
  • disclosed11 Dec 2013
  • creditUnknown

Introduced: 11 Dec 2013

CVE-2013-7086  (opens in a new tab)
CWE-77  (opens in a new tab)

Overview

webbynode is a Webbynode Deployment Gem. Affected versions of this gem contain a flaw in notify.rb that is triggered when handling a specially crafted growlnotify message. This may allow a context-dependent attacker to execute arbitrary commands.

CVSS Base Scores

version 3.1