In Mechanize, from v2.0.0 until v2.7.7, there is a command injection
vulnerability. Affected versions of Mechanize allow for OS commands to be
injected using several classes' methods which implicitly use Ruby's Kernel#open
method (CVE-2021-21289).
- https://bugs.mageia.org/show_bug.cgi?id=28448
- https://lists.debian.org/debian-lts-announce/2021/02/msg00021.html
- https://www.cve.org/CVERecord?id=CVE-2021-21289
- 7/core/ruby-mechanize-2.7.6-2.1.mga7
- 8/core/ruby-mechanize-2.7.6-3.1.mga8
Get the latest Linux and open source security news straight to your inbox.