Vuln
·
Scope
Home
Packages
KEV
Critical
Insights
Jobs
Pricing
EN
中
Loading…
RubyGems/bundler — 5 CVEs · VulnScope
pkg:RubyGems/
bundler
5 total CVEs
CRITICAL
1
HIGH
2
MEDIUM
1
✅ Check your installed version
Check
All known vulnerabilities
CRITICAL
9.8
CVE-2016-7954
Bundler allows attacker to inject arbitrary code via secondary Gem source
>= 1.0.0, < 2.0.0
HIGH
8.8
CVE-2020-36327
Dependency Confusion in Bundler
>= 1.16.0, < 2.2.10
HIGH
7.0
CVE-2019-3881
Insecure path handling in Bundler
>= 1.14.0, < 2.1.0
MEDIUM
6.7
rubygems - security update
from 0, < 2.2.33
—
Bundler may install gems from a different source than expected
from 0, < 1.7.0
CVE-2021-43809
CVE-2013-0334