Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2013-0334

Опубликовано: 31 окт. 2014
Источник: nvd
CVSS2: 5
EPSS Низкий

Описание

Bundler before 1.7, when multiple top-level source lines are used, allows remote attackers to install arbitrary gems by creating a gem with the same name as another gem in a different source.

Ссылки

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:bundler:bundler:*:*:*:*:*:ruby:*:*
Версия до 1.7.0 (исключая)
Конфигурация 2

Одно из

cpe:2.3:o:opensuse:opensuse:13.1:*:*:*:*:*:*:*
cpe:2.3:o:opensuse:opensuse:13.2:*:*:*:*:*:*:*
Конфигурация 3

Одно из

cpe:2.3:o:fedoraproject:fedora:19:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:20:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:21:*:*:*:*:*:*:*

EPSS

Процентиль: 65%
0.00498
Низкий

5 Medium

CVSS2

Дефекты

CWE-20

Связанные уязвимости

ubuntu
почти 11 лет назад

Bundler before 1.7, when multiple top-level source lines are used, allows remote attackers to install arbitrary gems by creating a gem with the same name as another gem in a different source.

redhat
около 11 лет назад

Bundler before 1.7, when multiple top-level source lines are used, allows remote attackers to install arbitrary gems by creating a gem with the same name as another gem in a different source.

debian
почти 11 лет назад

Bundler before 1.7, when multiple top-level source lines are used, all ...

suse-cvrf
больше 10 лет назад

Security update for rubygem-bundler

github
больше 3 лет назад

Bundler may install gems from a different source than expected

EPSS

Процентиль: 65%
0.00498
Низкий

5 Medium

CVSS2

Дефекты

CWE-20