CVE-2012-2140 describes a critical command injection vulnerability in the Ruby Mail gem versions prior to 2.4.3, affecting applications utilizing its sendmail or exim delivery methods. This flaw allows unauthenticated remote attackers to execute arbitrary shell commands due to improper handling of metacharacters. With a CVSS score of 7.5, this vulnerability presents a high risk of compromise, enabling full confidentiality, integrity, and availability impact. While no public exploits or active exploitation have been identified, and community discussion is minimal, the potential for severe impact necessitates patching.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2.4.1CPE matchmatch criteria | cpe:2.3:a:rubygems:mail_gem:*:*:*:*:*:*:*:* | ||
2.3.2CPE matchmatch criteria | cpe:2.3:a:rubygems:mail_gem:2.3.2:*:*:*:*:*:*:* | ||
2.3.3CPE matchmatch criteria | cpe:2.3:a:rubygems:mail_gem:2.3.3:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:P/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.