CVE-2017-10784
Last modified
CVE-2017-10784 is a vulnerability of currently unknown severity. The Basic authentication code in WEBrick library in Ruby before 2.2.8, 2.3.x before 2.3.5, and 2.4.x through 2.4.1 allows remote attackers to inject terminal emulator escape sequences into its log and possibly execute arbitrary commands via a crafted user name.. EPSS estimates a 16.41% chance of exploitation in the next 30 days.
Description
The Basic authentication code in WEBrick library in Ruby before 2.2.8, 2.3.x before 2.3.5, and 2.4.x through 2.4.1 allows remote attackers to inject terminal emulator escape sequences into its log and possibly execute arbitrary commands via a crafted user name.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Ruby-Lang | Ruby | <= 2.2.7 |
| Ruby-Lang | Ruby | 2.3.0 |
| Ruby-Lang | Ruby | 2.3.1 |
| Ruby-Lang | Ruby | 2.3.2 |
| Ruby-Lang | Ruby | 2.3.3 |
| Ruby-Lang | Ruby | 2.3.4 |
| Ruby-Lang | Ruby | 2.4.0 |
| Ruby-Lang | Ruby | 2.4.1 |
References
- http://www.securityfocus.com/bid/100853Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1039363Third Party Advisory, VDB Entry
- https://www.ruby-lang.org/en/news/2017/09/14/ruby-2-2-8-released/Patch, Vendor Advisory
- https://www.ruby-lang.org/en/news/2017/09/14/ruby-2-3-5-released/Patch, Vendor Advisory
- http://www.securityfocus.com/bid/100853Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1039363Third Party Advisory, VDB Entry
- https://www.ruby-lang.org/en/news/2017/09/14/ruby-2-2-8-released/Patch, Vendor Advisory
- https://www.ruby-lang.org/en/news/2017/09/14/ruby-2-3-5-released/Patch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2017-10784?
How severe is CVE-2017-10784?
How do I fix CVE-2017-10784?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2017
- CVE-2017-10779XnView Classic for Windows Version 2.40 might allow attacker…
- CVE-2017-1078Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2017-10780XnView Classic for Windows Version 2.40 might allow attacker…
- CVE-2017-10781XnView Classic for Windows Version 2.40 might allow attacker…
- CVE-2017-10782XnView Classic for Windows Version 2.40 might allow attacker…
- CVE-2017-10783XnView Classic for Windows Version 2.40 might allow attacker…
- CVE-2017-10788The DBD::mysql module through 4.043 for Perl allows remote a…
- CVE-2017-10789The DBD::mysql module through 4.043 for Perl uses the mysql_…
- CVE-2017-1079Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2017-10790The _asn1_check_identifier function in GNU Libtasn1 through …
- CVE-2017-10791There is an Integer overflow in the hash_int function of the…
- CVE-2017-10792There is a NULL Pointer Dereference in the function ll_inser…
Are you affected by CVE-2017-10784?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
