An issue was discovered in RubyGems 2.6 and later through 3.0.2. Since Gem::CommandManager#run calls alert_error without escaping, escape sequence injection is possible. (There are many ways to cause an error.)
| Product | Vendor | Version |
|---|---|---|
| n/a | n/a | < f0ed2d0abc021f56fa27dc6d0770535c1851a43b |
| n/a | n/a | Snapdragon AR1 Gen 1 Platform "Luna1" |