Bundler 1.x might allow remote attackers to inject arbitrary Ruby code into an application by leveraging a gem name collision on a secondary source. NOTE: this might overlap CVE-2013-0334.
References
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2016-12-22 22:59
Updated : 2025-04-12 10:46
NVD link : CVE-2016-7954
Mitre link : CVE-2016-7954
CVE.ORG link : CVE-2016-7954
JSON object : View
Products Affected
bundler
- bundler
CWE
CWE-94
Improper Control of Generation of Code ('Code Injection')