bundler
RubyGems5 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting bundlerpage 1 of 1
- CVE-2013-0334NONECVSS 0.0EG 0.0✓ Fixed in 1.7.02014-10-31
vulnerable: 0.3.0 ... 1.6.9 (150 versions)
Bundler before 1.7, when multiple top-level source lines are used, allows remote attackers to install arbitrary gems by creating a gem with the same name as another gem in a different source.
- CVE-2016-7954CRITICALCVSS 9.8EG 9.8✓ Fixed in 2.0.02016-12-22
vulnerable: 1.0.0 ... 2.0.0.pre.3 (212 versions)
Bundler 1.x might allow remote attackers to inject arbitrary Ruby code into an application by leveraging a gem name collision on a secondary source. NOTE: this might overlap CVE-2013-0334.
- CVE-2019-3881HIGHCVSS 7.8EG 7.8✓ Fixed in 2.1.02020-09-04
vulnerable: 1.14.0 ... 2.1.0.pre.3 (41 versions)
Bundler prior to 2.1.0 uses a predictable path in /tmp/, created with insecure permissions as a storage location for gems, if locations under the user's home directory are not available. If Bundler is used in a scenario where the user does…
- CVE-2020-36327HIGHCVSS 8.8EG 8.8✓ Fixed in 2.2.182021-04-29
vulnerable: 2.2.11 ... 2.2.17 (7 versions)
Bundler 1.16.0 through 2.2.9 and 2.2.11 through 2.2.16 sometimes chooses a dependency source based on the highest gem version number, which means that a rogue gem found at a public source may be chosen, even if the intended choice was a pr…
- CVE-2021-43809MEDIUMCVSS 6.7EG 6.7✓ Fixed in 2.2.332021-12-08
vulnerable: 0.3.0 ... 2.2.9 (317 versions)
`Bundler` is a package for managing application dependencies in Ruby. In `bundler` versions before 2.2.33, when working with untrusted and apparently harmless `Gemfile`'s, it is not expected that they lead to execution of external code, un…
Check whether bundler is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for bundler CVEs against the assets you own.
Start Free Scan →