CVE-2021-43809
- EPSS 1.81%
- Veröffentlicht 08.12.2021 19:15:10
- Zuletzt bearbeitet 21.11.2024 06:29:50
`Bundler` is a package for managing application dependencies in Ruby. In `bundler` versions before 2.2.33, when working with untrusted and apparently harmless `Gemfile`'s, it is not expected that they lead to execution of external code, unless that's...
CVE-2020-36327
- EPSS 15.57%
- Veröffentlicht 29.04.2021 03:15:08
- Zuletzt bearbeitet 21.11.2024 05:29:17
Bundler 1.16.0 through 2.2.9 and 2.2.11 through 2.2.16 sometimes chooses a dependency source based on the highest gem version number, which means that a rogue gem found at a public source may be chosen, even if the intended choice was a private gem t...
CVE-2019-3881
- EPSS 0.1%
- Veröffentlicht 04.09.2020 12:15:10
- Zuletzt bearbeitet 21.11.2024 04:42:47
Bundler prior to 2.1.0 uses a predictable path in /tmp/, created with insecure permissions as a storage location for gems, if locations under the user's home directory are not available. If Bundler is used in a scenario where the user does not have a...
CVE-2016-7954
- EPSS 2.78%
- Veröffentlicht 22.12.2016 22:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
Bundler 1.x might allow remote attackers to inject arbitrary Ruby code into an application by leveraging a gem name collision on a secondary source. NOTE: this might overlap CVE-2013-0334.
- EPSS 0.5%
- Veröffentlicht 31.10.2014 14:55:02
- Zuletzt bearbeitet 12.04.2025 10:46:40
Bundler before 1.7, when multiple top-level source lines are used, allows remote attackers to install arbitrary gems by creating a gem with the same name as another gem in a different source.