An open API service providing security vulnerability metadata for many open source software ecosystems.

GSA_kwCzR0hTQS1tcWNwLXAyaHYtdnc2eM4ABKTX

Low EPSS: 0.0002% (0.03682 Percentile) EPSS:

Thor can construct an unsafe shell command from library input.

Affected Packages Affected Versions Fixed Versions
rubygems:thor < 1.4.0 1.4.0
6,418 Dependent packages
952,392 Dependent repositories
947,212,188 Downloads total

Affected Version Ranges

All affected versions

0.9.2, 0.9.5, 0.9.6, 0.9.7, 0.9.8, 0.9.9, 0.11.5, 0.11.6, 0.11.7, 0.11.8, 0.12.0, 0.12.2, 0.12.3, 0.13.0, 0.13.1, 0.13.2, 0.13.3, 0.13.4, 0.13.5, 0.13.6, 0.13.7, 0.13.8, 0.14.0, 0.14.1, 0.14.2, 0.14.3, 0.14.4, 0.14.5, 0.14.6, 0.15.0, 0.15.1, 0.15.2, 0.15.3, 0.15.4, 0.16.0, 0.17.0, 0.18.0, 0.18.1, 0.19.0, 0.19.1, 0.19.2, 0.19.3, 0.19.4, 0.20.0, 0.20.1, 0.20.2, 0.20.3, 1.0.0, 1.0.1, 1.1.0, 1.2.0, 1.2.1, 1.2.2, 1.3.0, 1.3.1, 1.3.2

All unaffected versions

1.4.0