{"id":"CVE-2021-35514","aliases":[],"url":"https://o3.security/vulnerability/CVE-2021-35514","summary":"Code injection in Narou","details":"Narou (aka Narou.rb) before 3.8.0 allows Ruby Code Injection via the title name or author name of a novel.","published":"2021-07-02T18:36:01Z","modified":"2023-11-08T04:06:10.193384Z","cvss":{"score":8.5,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[{"ecosystem":"RubyGems","name":"narou","fixedVersion":"3.8.0"}],"fix":{"url":"https://github.com/whiteleaf7/narou/commit/d07720e855293182563b749431dfbf6c2d1cdb42","label":"whiteleaf7/narou@d07720e"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2021-35514"},{"type":"WEB","url":"https://github.com/whiteleaf7/narou/commit/d07720e855293182563b749431dfbf6c2d1cdb42"},{"type":"PACKAGE","url":"https://github.com/whiteleaf7/narou"},{"type":"WEB","url":"https://github.com/whiteleaf7/narou/blob/develop/ChangeLog.md#380-20210627"},{"type":"WEB","url":"https://vuln.ryotak.me/advisories/51"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2023-11-08T04:06:10.193384Z"}}