Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 41

Количество 41

ubuntu логотип

CVE-2020-36327

больше 5 лет назад

Bundler 1.16.0 through 2.2.9 and 2.2.11 through 2.2.16 sometimes chooses a dependency source based on the highest gem version number, which means that a rogue gem found at a public source may be chosen, even if the intended choice was a private gem that is a dependency of another private gem that is explicitly depended on by the application. NOTE: it is not correct to use CVE-2021-24105 for every "Dependency Confusion" issue in every product.

CVSS3: 8.8
EPSS: Низкий
redhat логотип

CVE-2020-36327

больше 5 лет назад

Bundler 1.16.0 through 2.2.9 and 2.2.11 through 2.2.16 sometimes chooses a dependency source based on the highest gem version number, which means that a rogue gem found at a public source may be chosen, even if the intended choice was a private gem that is a dependency of another private gem that is explicitly depended on by the application. NOTE: it is not correct to use CVE-2021-24105 for every "Dependency Confusion" issue in every product.

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2020-36327

больше 5 лет назад

Bundler 1.16.0 through 2.2.9 and 2.2.11 through 2.2.16 sometimes chooses a dependency source based on the highest gem version number, which means that a rogue gem found at a public source may be chosen, even if the intended choice was a private gem that is a dependency of another private gem that is explicitly depended on by the application. NOTE: it is not correct to use CVE-2021-24105 for every "Dependency Confusion" issue in every product.

CVSS3: 8.8
EPSS: Низкий
debian логотип

CVE-2020-36327

больше 5 лет назад

Bundler 1.16.0 through 2.2.9 and 2.2.11 through 2.2.16 sometimes choos ...

CVSS3: 8.8
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:1294-1

больше 1 года назад

Security update for rubygem-bundler

EPSS: Низкий
rocky логотип

RLSA-2022:0545

больше 4 лет назад

Important: ruby:2.5 security update

EPSS: Низкий
github логотип

GHSA-fp4w-jxhp-m23p

около 5 лет назад

Dependency Confusion in Bundler

CVSS3: 8.8
EPSS: Низкий
oracle-oval логотип

ELSA-2022-0545

больше 4 лет назад

ELSA-2022-0545: ruby:2.5 security update (IMPORTANT)

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:1355-1

4 месяца назад

Security update for rubygem-bundler

EPSS: Низкий
ubuntu логотип

CVE-2021-31799

около 5 лет назад

In RDoc 3.11 through 6.x before 6.3.1, as distributed with Ruby through 3.0.1, it is possible to execute arbitrary code via | and tags in a filename.

CVSS3: 7
EPSS: Низкий
redhat логотип

CVE-2021-31799

около 5 лет назад

In RDoc 3.11 through 6.x before 6.3.1, as distributed with Ruby through 3.0.1, it is possible to execute arbitrary code via | and tags in a filename.

CVSS3: 7
EPSS: Низкий
nvd логотип

CVE-2021-31799

около 5 лет назад

In RDoc 3.11 through 6.x before 6.3.1, as distributed with Ruby through 3.0.1, it is possible to execute arbitrary code via | and tags in a filename.

CVSS3: 7
EPSS: Низкий
debian логотип

CVE-2021-31799

около 5 лет назад

In RDoc 3.11 through 6.x before 6.3.1, as distributed with Ruby throug ...

CVSS3: 7
EPSS: Низкий
ubuntu логотип

CVE-2021-31810

около 5 лет назад

An issue was discovered in Ruby through 2.6.7, 2.7.x through 2.7.3, and 3.x through 3.0.1. A malicious FTP server can use the PASV response to trick Net::FTP into connecting back to a given IP address and port. This potentially makes curl extract information about services that are otherwise private and not disclosed (e.g., the attacker can conduct port scans and service banner extractions).

CVSS3: 5.8
EPSS: Низкий
redhat логотип

CVE-2021-31810

около 5 лет назад

An issue was discovered in Ruby through 2.6.7, 2.7.x through 2.7.3, and 3.x through 3.0.1. A malicious FTP server can use the PASV response to trick Net::FTP into connecting back to a given IP address and port. This potentially makes curl extract information about services that are otherwise private and not disclosed (e.g., the attacker can conduct port scans and service banner extractions).

CVSS3: 5.4
EPSS: Низкий
nvd логотип

CVE-2021-31810

около 5 лет назад

An issue was discovered in Ruby through 2.6.7, 2.7.x through 2.7.3, and 3.x through 3.0.1. A malicious FTP server can use the PASV response to trick Net::FTP into connecting back to a given IP address and port. This potentially makes curl extract information about services that are otherwise private and not disclosed (e.g., the attacker can conduct port scans and service banner extractions).

CVSS3: 5.8
EPSS: Низкий
debian логотип

CVE-2021-31810

около 5 лет назад

An issue was discovered in Ruby through 2.6.7, 2.7.x through 2.7.3, an ...

CVSS3: 5.8
EPSS: Низкий
github логотип

GHSA-ggxm-pgc9-g7fp

почти 5 лет назад

Arbitrary Code Execution in Rdoc

CVSS3: 7
EPSS: Низкий
fstec логотип

BDU:2021-05398

около 5 лет назад

Уязвимость встроенного генератора документации RDoc для языка программирования Ruby, позволяющая нарушителю выполнить произвольные команды

CVSS3: 7
EPSS: Низкий
github логотип

GHSA-wr95-679j-87v9

около 4 лет назад

An issue was discovered in Ruby through 2.6.7, 2.7.x through 2.7.3, and 3.x through 3.0.1. A malicious FTP server can use the PASV response to trick Net::FTP into connecting back to a given IP address and port. This potentially makes curl extract information about services that are otherwise private and not disclosed (e.g., the attacker can conduct port scans and service banner extractions).

CVSS3: 5.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2020-36327

Bundler 1.16.0 through 2.2.9 and 2.2.11 through 2.2.16 sometimes chooses a dependency source based on the highest gem version number, which means that a rogue gem found at a public source may be chosen, even if the intended choice was a private gem that is a dependency of another private gem that is explicitly depended on by the application. NOTE: it is not correct to use CVE-2021-24105 for every "Dependency Confusion" issue in every product.

CVSS3: 8.8
6%
Низкий
больше 5 лет назад
redhat логотип
CVE-2020-36327

Bundler 1.16.0 through 2.2.9 and 2.2.11 through 2.2.16 sometimes chooses a dependency source based on the highest gem version number, which means that a rogue gem found at a public source may be chosen, even if the intended choice was a private gem that is a dependency of another private gem that is explicitly depended on by the application. NOTE: it is not correct to use CVE-2021-24105 for every "Dependency Confusion" issue in every product.

CVSS3: 8.8
6%
Низкий
больше 5 лет назад
nvd логотип
CVE-2020-36327

Bundler 1.16.0 through 2.2.9 and 2.2.11 through 2.2.16 sometimes chooses a dependency source based on the highest gem version number, which means that a rogue gem found at a public source may be chosen, even if the intended choice was a private gem that is a dependency of another private gem that is explicitly depended on by the application. NOTE: it is not correct to use CVE-2021-24105 for every "Dependency Confusion" issue in every product.

CVSS3: 8.8
6%
Низкий
больше 5 лет назад
debian логотип
CVE-2020-36327

Bundler 1.16.0 through 2.2.9 and 2.2.11 through 2.2.16 sometimes choos ...

CVSS3: 8.8
6%
Низкий
больше 5 лет назад
suse-cvrf логотип
SUSE-SU-2025:1294-1

Security update for rubygem-bundler

6%
Низкий
больше 1 года назад
rocky логотип
RLSA-2022:0545

Important: ruby:2.5 security update

6%
Низкий
больше 4 лет назад
github логотип
GHSA-fp4w-jxhp-m23p

Dependency Confusion in Bundler

CVSS3: 8.8
6%
Низкий
около 5 лет назад
oracle-oval логотип
ELSA-2022-0545

ELSA-2022-0545: ruby:2.5 security update (IMPORTANT)

больше 4 лет назад
suse-cvrf логотип
SUSE-SU-2026:1355-1

Security update for rubygem-bundler

4 месяца назад
ubuntu логотип
CVE-2021-31799

In RDoc 3.11 through 6.x before 6.3.1, as distributed with Ruby through 3.0.1, it is possible to execute arbitrary code via | and tags in a filename.

CVSS3: 7
1%
Низкий
около 5 лет назад
redhat логотип
CVE-2021-31799

In RDoc 3.11 through 6.x before 6.3.1, as distributed with Ruby through 3.0.1, it is possible to execute arbitrary code via | and tags in a filename.

CVSS3: 7
1%
Низкий
около 5 лет назад
nvd логотип
CVE-2021-31799

In RDoc 3.11 through 6.x before 6.3.1, as distributed with Ruby through 3.0.1, it is possible to execute arbitrary code via | and tags in a filename.

CVSS3: 7
1%
Низкий
около 5 лет назад
debian логотип
CVE-2021-31799

In RDoc 3.11 through 6.x before 6.3.1, as distributed with Ruby throug ...

CVSS3: 7
1%
Низкий
около 5 лет назад
ubuntu логотип
CVE-2021-31810

An issue was discovered in Ruby through 2.6.7, 2.7.x through 2.7.3, and 3.x through 3.0.1. A malicious FTP server can use the PASV response to trick Net::FTP into connecting back to a given IP address and port. This potentially makes curl extract information about services that are otherwise private and not disclosed (e.g., the attacker can conduct port scans and service banner extractions).

CVSS3: 5.8
3%
Низкий
около 5 лет назад
redhat логотип
CVE-2021-31810

An issue was discovered in Ruby through 2.6.7, 2.7.x through 2.7.3, and 3.x through 3.0.1. A malicious FTP server can use the PASV response to trick Net::FTP into connecting back to a given IP address and port. This potentially makes curl extract information about services that are otherwise private and not disclosed (e.g., the attacker can conduct port scans and service banner extractions).

CVSS3: 5.4
3%
Низкий
около 5 лет назад
nvd логотип
CVE-2021-31810

An issue was discovered in Ruby through 2.6.7, 2.7.x through 2.7.3, and 3.x through 3.0.1. A malicious FTP server can use the PASV response to trick Net::FTP into connecting back to a given IP address and port. This potentially makes curl extract information about services that are otherwise private and not disclosed (e.g., the attacker can conduct port scans and service banner extractions).

CVSS3: 5.8
3%
Низкий
около 5 лет назад
debian логотип
CVE-2021-31810

An issue was discovered in Ruby through 2.6.7, 2.7.x through 2.7.3, an ...

CVSS3: 5.8
3%
Низкий
около 5 лет назад
github логотип
GHSA-ggxm-pgc9-g7fp

Arbitrary Code Execution in Rdoc

CVSS3: 7
1%
Низкий
почти 5 лет назад
fstec логотип
BDU:2021-05398

Уязвимость встроенного генератора документации RDoc для языка программирования Ruby, позволяющая нарушителю выполнить произвольные команды

CVSS3: 7
1%
Низкий
около 5 лет назад
github логотип
GHSA-wr95-679j-87v9

An issue was discovered in Ruby through 2.6.7, 2.7.x through 2.7.3, and 3.x through 3.0.1. A malicious FTP server can use the PASV response to trick Net::FTP into connecting back to a given IP address and port. This potentially makes curl extract information about services that are otherwise private and not disclosed (e.g., the attacker can conduct port scans and service banner extractions).

CVSS3: 5.8
3%
Низкий
около 4 лет назад

Уязвимостей на страницу