Lack of data validation In bundler
Description
Bundler may install gems from a different source than expected Bundler before 1.7, when multiple top-level source lines are used, allows remote attackers to install arbitrary gems by creating a gem with the same name as another gem in a different source.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
rubygems | 1.7.0 | ||
rpm rhel7 | 0:0.19.1-1.el7 | ||
rpm rhel7 | 0:1.7.8-3.el7 |
Aliases
1. 2. 3. 4. 5.
References
1. 2. 3. 4. 5. 6. 7. 8.