Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-49jx-9cmc-xjxm

Опубликовано: 05 мая 2022
Источник: github
Github: Прошло ревью

Описание

Bundler may install gems from a different source than expected

Bundler before 1.7, when multiple top-level source lines are used, allows remote attackers to install arbitrary gems by creating a gem with the same name as another gem in a different source.

Пакеты

Наименование

bundler

rubygems
Затронутые версииВерсия исправления

< 1.7.0

1.7.0

EPSS

Процентиль: 65%
0.00498
Низкий

Дефекты

CWE-20

Связанные уязвимости

ubuntu
почти 11 лет назад

Bundler before 1.7, when multiple top-level source lines are used, allows remote attackers to install arbitrary gems by creating a gem with the same name as another gem in a different source.

redhat
около 11 лет назад

Bundler before 1.7, when multiple top-level source lines are used, allows remote attackers to install arbitrary gems by creating a gem with the same name as another gem in a different source.

nvd
почти 11 лет назад

Bundler before 1.7, when multiple top-level source lines are used, allows remote attackers to install arbitrary gems by creating a gem with the same name as another gem in a different source.

debian
почти 11 лет назад

Bundler before 1.7, when multiple top-level source lines are used, all ...

suse-cvrf
больше 10 лет назад

Security update for rubygem-bundler

EPSS

Процентиль: 65%
0.00498
Низкий

Дефекты

CWE-20