Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-21654

Опубликовано: 12 янв. 2024
Источник: nvd
CVSS3: 4.8
CVSS3: 9.8
EPSS Низкий

Описание

Rubygems.org is the Ruby community's gem hosting service. Rubygems.org users with MFA enabled would normally be protected from account takeover in the case of email account takeover. However, a workaround on the forgotten password form allows an attacker to bypass the MFA requirement and takeover the account. This vulnerability has been patched in commit 0b3272a.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:rubygems:rubygems.org:*:*:*:*:*:*:*:*
Версия до 2024-01-08 (исключая)

EPSS

Процентиль: 33%
0.00129
Низкий

4.8 Medium

CVSS3

9.8 Critical

CVSS3

Дефекты

CWE-287
CWE-306

Связанные уязвимости

CVSS3: 4.8
redhat
около 2 лет назад

Rubygems.org is the Ruby community's gem hosting service. Rubygems.org users with MFA enabled would normally be protected from account takeover in the case of email account takeover. However, a workaround on the forgotten password form allows an attacker to bypass the MFA requirement and takeover the account. This vulnerability has been patched in commit 0b3272a.

EPSS

Процентиль: 33%
0.00129
Низкий

4.8 Medium

CVSS3

9.8 Critical

CVSS3

Дефекты

CWE-287
CWE-306