BibTeX-Ruby vulnerable to OS command injection
Critical severity
GitHub Reviewed
Published
Feb 14, 2020
to the GitHub Advisory Database
•
Updated Aug 28, 2023
Description
Reviewed
Feb 13, 2020
Published to the GitHub Advisory Database
Feb 14, 2020
Last updated
Aug 28, 2023
BibTeX-ruby before 5.1.0 allows shell command injection due to unsanitized user input being passed directly to the built-in Ruby
Kernel.open
method through BibTeX.open.References