Bundler before 1.7, when multiple top-level source lines are used, allows remote attackers to install arbitrary gems by creating a gem with the same name as another gem in a different source.
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
History
No history.
Information
Published : 2014-10-31 14:55
Updated : 2025-04-12 10:46
NVD link : CVE-2013-0334
Mitre link : CVE-2013-0334
CVE.ORG link : CVE-2013-0334
JSON object : View
Products Affected
opensuse
- opensuse
bundler
- bundler
fedoraproject
- fedora
CWE
CWE-20
Improper Input Validation