Search CVE reports


Toggle filters

1 – 5 of 5 results


CVE-2021-43809

Medium priority
Vulnerable

`Bundler` is a package for managing application dependencies in Ruby. In `bundler` versions before 2.2.33, when working with untrusted and apparently harmless `Gemfile`'s, it is not expected that they lead to execution of external...

1 affected package

bundler

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
bundler Not in release Not in release Not in release Vulnerable Vulnerable
Show less packages

CVE-2020-36327

Medium priority
Ignored

Bundler 1.16.0 through 2.2.9 and 2.2.11 through 2.2.16 sometimes chooses a dependency source based on the highest gem version number, which means that a rogue gem found at a public source may be chosen, even if the intended choice...

1 affected package

bundler

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
bundler Not in release Not in release Not in release Ignored Ignored
Show less packages

CVE-2019-3881

Medium priority
Fixed

Bundler prior to 2.1.0 uses a predictable path in /tmp/, created with insecure permissions as a storage location for gems, if locations under the user's home directory are not available. If Bundler is used in a scenario where the...

1 affected package

bundler

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
bundler Not in release Not affected Fixed
Show less packages

CVE-2016-7954

Medium priority
Vulnerable

Bundler 1.x might allow remote attackers to inject arbitrary Ruby code into an application by leveraging a gem name collision on a secondary source. NOTE: this might overlap CVE-2013-0334.

1 affected package

bundler

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
bundler Not in release Not in release Not in release Not affected Vulnerable
Show less packages

CVE-2013-0334

Medium priority
Ignored

Bundler before 1.7, when multiple top-level source lines are used, allows remote attackers to install arbitrary gems by creating a gem with the same name as another gem in a different source.

1 affected package

bundler

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
bundler Not affected
Show less packages