CVE-2013-2090

The set_meta_data function in lib/cremefraiche.rb in the Creme Fraiche gem before 0.6.1 for Ruby allows remote attackers to execute arbitrary commands via shell metacharacters in the file name of an email attachment.  NOTE: some of these details are obtained from third party information.
OS Command Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
9.3 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:C/I:C/A:C
redhatCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 80%
VendorProductVersion
uplawskicreme_fraiche
𝑥
≤ 0.6
uplawskicreme_fraiche
0.4.5
uplawskicreme_fraiche
0.4.5.1
uplawskicreme_fraiche
0.4.5.2
uplawskicreme_fraiche
0.4.5.4
uplawskicreme_fraiche
0.4.5.5
uplawskicreme_fraiche
0.4.5.6
uplawskicreme_fraiche
0.5
uplawskicreme_fraiche
0.5.1
uplawskicreme_fraiche
0.5.2
uplawskicreme_fraiche
0.5.3
𝑥
= Vulnerable software versions