VDB

SNYK-RUBY-BUNDLER-1078261

SNYK-RUBY-BUNDLER-1078261 PUBLISHED CVSS 8.899999618530273 HIGH

## Overview Affected versions of this package are vulnerable to Unsafe Dependency Resolution. An issue exist in bundler regarding the priority for transitive dependencies and split lockfile rubygems source sections. This could lead to a dependency confusion attack where gems are resolved incorrectly. ## Remediation Upgrade `bundler` to version 2.2.10, 2.2.16 or higher. ## References - [Dependency Confusion](https://medium.com/@alex.birsan/dependency-confusion-4a5d60fec610) - [GitHub Changelog](https://github.com/rubygems/rubygems/blob/master/bundler/CHANGELOG.md#security-fixes) - [GitHub PR](https://github.com/rubygems/rubygems/pull/3655) - [RubyGems dependency confusion attack side of things](https://mensfeld.pl/2021/02/rubygems-dependency-confusion-attack-side-of-things/)

Risk Scores

CVSS v3.1
8.899999618530273
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:L/E:U/RL:O/RC:R

Affected Products

VendorProductVersions

Timeline

  • Feb 15, 2021 CVE Updated
  • Feb 22, 2021 CVE Published
Open in Interactive Console →
$ Console Community · 100/wk Open console ›