Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2013-0334

Опубликовано: 14 авг. 2014
Источник: redhat
CVSS2: 5.1
EPSS Низкий

Описание

Bundler before 1.7, when multiple top-level source lines are used, allows remote attackers to install arbitrary gems by creating a gem with the same name as another gem in a different source.

A flaw was found in the way Bundler handled gems available from multiple sources. An attacker with access to one of the sources could create a malicious gem with the same name, which they could then use to trick a user into installing, potentially resulting in execution of code from the attacker-supplied malicious gem.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
CloudForms Management Engine 5ruby193-rubygem-bundlerWill not fix
OpenShift Enterprise 1ruby193-rubygem-bundlerWill not fix
OpenShift Enterprise 1rubygem-bundlerWill not fix
OpenStack Foremanrubygem-bundlerWill not fix
Red Hat OpenShift Enterprise 2rubygem-bundlerWill not fix
Red Hat OpenStack Platform 4ruby193-rubygem-bundlerWill not fix
Red Hat Software Collectionsror40-rubygem-bundlerWill not fix
Red Hat Software Collectionsruby193-rubygem-bundlerWill not fix
Red Hat Subscription Asset Managerruby193-rubygem-bundlerWill not fix
Red Hat Enterprise Linux 7rubygem-bundlerFixedRHSA-2015:218019.11.2015

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-345
https://bugzilla.redhat.com/show_bug.cgi?id=1146335rubygem-bundler: 'bundle install' may install a gem from a source other than expected

EPSS

Процентиль: 65%
0.00498
Низкий

5.1 Medium

CVSS2

Связанные уязвимости

ubuntu
почти 11 лет назад

Bundler before 1.7, when multiple top-level source lines are used, allows remote attackers to install arbitrary gems by creating a gem with the same name as another gem in a different source.

nvd
почти 11 лет назад

Bundler before 1.7, when multiple top-level source lines are used, allows remote attackers to install arbitrary gems by creating a gem with the same name as another gem in a different source.

debian
почти 11 лет назад

Bundler before 1.7, when multiple top-level source lines are used, all ...

suse-cvrf
больше 10 лет назад

Security update for rubygem-bundler

github
больше 3 лет назад

Bundler may install gems from a different source than expected

EPSS

Процентиль: 65%
0.00498
Низкий

5.1 Medium

CVSS2