CVE-2019-3881 PUBLISHED

Bundler prior to 2.1.0 uses a predictable path in /tmp/, created with insecure permissions as a storage location for gems, if locations under the user's home directory are not available. If Bundler is used in a scenario where the user does not have a writable home directory, an attacker could place malicious code in this directory that would be later loaded and executed.

EPSS 0.15% · 35.6th percentile

Risk Scores

EPSS Score
0.15%
35.6th percentile

Affected Products

VendorProductVersions
Ubuntu:Pro:18.04:LTSbundler0, 1.15.1-1, 1.16.1-1

Timeline

References

Open in Interactive Console →