« Back to list

CVE-2017-10784

Status: ModifiedHigh (8.8)—

The Basic authentication code in WEBrick library in Ruby before 2.2.8, 2.3.x before 2.3.5, and 2.4.x through 2.4.1 allows remote attackers to inject terminal emulator escape sequences into its log and possibly execute arbitrary commands via a crafted user name.

CVSS

Exploitation probability (EPSS)

EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).

Affected technologies (1)

CWEs

References

Raw JSON (NVD)

Show
{
  "id": "CVE-2017-10784",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 9.3,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "authentication": "NONE",
          "integrityImpact": "COMPLETE",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "COMPLETE",
          "confidentialityImpact": "COMPLETE"
        },
        "acInsufInfo": false,
        "impactScore": 10,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8.6,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": true
      }
    ],
    "cvssMetricV30": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.0",
          "baseScore": 8.8,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2017-09-19T17:29:00.263",
  "references": [
    {
      "url": "http://www.securityfocus.com/bid/100853",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securitytracker.com/id/1039363",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securitytracker.com/id/1042004",
      "source": "cve@mitre.org"
    },
    {
      "url": "https://access.redhat.com/errata/RHSA-2017:3485",
      "source": "cve@mitre.org"
    },
    {
      "url": "https://access.redhat.com/errata/RHSA-2018:0378",
      "source": "cve@mitre.org"
    },
    {
      "url": "https://access.redhat.com/errata/RHSA-2018:0583",
      "source": "cve@mitre.org"
    },
    {
      "url": "https://access.redhat.com/errata/RHSA-2018:0585",
      "source": "cve@mitre.org"
    },
    {
      "url": "https://lists.debian.org/debian-lts-announce/2018/07/msg00012.html",
      "source": "cve@mitre.org"
    },
    {
      "url": "https://security.gentoo.org/glsa/201710-18",
      "source": "cve@mitre.org"
    },
    {
      "url": "https://usn.ubuntu.com/3528-1/",
      "source": "cve@mitre.org"
    },
    {
      "url": "https://usn.ubuntu.com/3685-1/",
      "source": "cve@mitre.org"
    },
    {
      "url": "https://www.debian.org/security/2017/dsa-4031",
      "source": "cve@mitre.org"
    },
    {
      "url": "https://www.ruby-lang.org/en/news/2017/09/14/ruby-2-2-8-released/",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://www.ruby-lang.org/en/news/2017/09/14/ruby-2-3-5-released/",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://www.ruby-lang.org/en/news/2017/09/14/webrick-basic-auth-escape-sequence-injection-cve-2017-10784/",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/bid/100853",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securitytracker.com/id/1039363",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securitytracker.com/id/1042004",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://access.redhat.com/errata/RHSA-2017:3485",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://access.redhat.com/errata/RHSA-2018:0378",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://access.redhat.com/errata/RHSA-2018:0583",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://access.redhat.com/errata/RHSA-2018:0585",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://lists.debian.org/debian-lts-announce/2018/07/msg00012.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://security.gentoo.org/glsa/201710-18",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://usn.ubuntu.com/3528-1/",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://usn.ubuntu.com/3685-1/",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.debian.org/security/2017/dsa-4031",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.ruby-lang.org/en/news/2017/09/14/ruby-2-2-8-released/",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.ruby-lang.org/en/news/2017/09/14/ruby-2-3-5-released/",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.ruby-lang.org/en/news/2017/09/14/webrick-basic-auth-escape-sequence-injection-cve-2017-10784/",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-287"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "The Basic authentication code in WEBrick library in Ruby before 2.2.8, 2.3.x before 2.3.5, and 2.4.x through 2.4.1 allows remote attackers to inject terminal emulator escape sequences into its log and possibly execute arbitrary commands via a crafted user name."
    },
    {
      "lang": "es",
      "value": "El código de autenticación Basic en la biblioteca WEBrick en Ruby en versiones anteriores a la 2.2.8, 2.3.x anteriores a la 2.3.5 y 2.4.x hasta la 2.4.1 permite que atacantes remotos inyecten secuencias de escape del emulador del terminal en su registro y que puedan ejecutar comandos arbitrarios mediante un nombre de usuario manipulado."
    }
  ],
  "lastModified": "2026-06-17T01:00:42.297",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:ruby-lang:ruby:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "20D4B423-C141-4B08-9FE4-2ADCB868A224",
              "versionEndIncluding": "2.2.7"
            },
            {
              "criteria": "cpe:2.3:a:ruby-lang:ruby:2.3.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "822307DD-7F7D-44C2-9C4B-CB8704663410"
            },
            {
              "criteria": "cpe:2.3:a:ruby-lang:ruby:2.3.0:preview1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A2D62AC9-83B8-4C84-A47E-2B06C2816964"
            },
            {
              "criteria": "cpe:2.3:a:ruby-lang:ruby:2.3.0:preview2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E583E49C-95B1-4AE4-AA7A-6D6BA7D470B4"
            },
            {
              "criteria": "cpe:2.3:a:ruby-lang:ruby:2.3.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5F197C5A-2588-417F-A743-E72D1E8EF4F7"
            },
            {
              "criteria": "cpe:2.3:a:ruby-lang:ruby:2.3.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "FBA01BF1-91AD-4968-9AC2-A194FCD6AB76"
            },
            {
              "criteria": "cpe:2.3:a:ruby-lang:ruby:2.3.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B36CCD91-2A20-4C2E-96D5-73704DFC10E4"
            },
            {
              "criteria": "cpe:2.3:a:ruby-lang:ruby:2.3.4:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "485C401C-CC3B-4A74-82D6-F4539FFE48B8"
            },
            {
              "criteria": "cpe:2.3:a:ruby-lang:ruby:2.4.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F9E99F5A-E693-43E9-8AB3-A3FCB21BCF14"
            },
            {
              "criteria": "cpe:2.3:a:ruby-lang:ruby:2.4.0:preview1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9DDA92E9-C9CF-47B9-B647-0202D493D057"
            },
            {
              "criteria": "cpe:2.3:a:ruby-lang:ruby:2.4.0:preview2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A682A487-A615-404C-A7D9-A28C0C31B4E7"
            },
            {
              "criteria": "cpe:2.3:a:ruby-lang:ruby:2.4.0:preview3:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8930BA64-E9BC-42E0-9D74-8FA2ABD1F692"
            },
            {
              "criteria": "cpe:2.3:a:ruby-lang:ruby:2.4.0:rc1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A87AE96A-F7FB-41A2-943C-DFAEA6D81446"
            },
            {
              "criteria": "cpe:2.3:a:ruby-lang:ruby:2.4.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "946D2AB0-D334-4D94-BDA2-733BFC6C9E1E"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}