Bundler before 1.7, when multiple top-level source lines are used, allows remote attackers to install arbitrary gems by creating a gem with the same name as another gem in a different source.
CVSS Details
- CVSS 3.1 Base Score: 5.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade ruby-actionmailer. | Aug 30, 2017 | Oct 31, 2014 |
| Gentoo Linux | — | Upgrade dev-ruby/bundler. | Oct 30, 2017 | Oct 31, 2014 |
| Oracle_linux | — | Upgrade rubygem-bundlerUpgrade rubygem-thorUpgrade rubygem-thor-docUpgrade rubygem-bundler-doc | Oct 16, 2024 | Oct 31, 2014 |
| Suse | — | Upgrade sle-sdk-releaseUpgrade rubygem-bundlerUpgrade sle-hae-releaseUpgrade rubygem-bundler-doc | Jun 4, 2015 | Oct 31, 2014 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub