CVE-2013-0334
published 2014-10-31CVE-2013-0334: Bundler before 1.7, when multiple top-level source lines are used, allows remote attackers to install arbitrary gems by creating a gem with the same name as…
PriorityP432medium5CVSS 2.0
AVNACLAuNCNIPAN
EPSS
3.85%
89.0th percentile
Bundler before 1.7, when multiple top-level source lines are used, allows remote attackers to install arbitrary gems by creating a gem with the same name as another gem in a different source.
Affected
125 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| bundler | bundler | < 1.7.0 | 1.7.0 |
| bundler | bundler | — | — |
| bundler | bundler | — | — |
| bundler | bundler | — | — |
| bundler | bundler | — | — |
| bundler | bundler | — | — |
| bundler | bundler | — | — |
| bundler | bundler | — | — |
| bundler | bundler | — | — |
| bundler | bundler | — | — |
| bundler | bundler | — | — |
| bundler | bundler | — | — |
| bundler | bundler | — | — |
| bundler | bundler | — | — |
| bundler | bundler | — | — |
| bundler | bundler | — | — |
| bundler | bundler | — | — |
| bundler | bundler | — | — |
| bundler | bundler | — | — |
| bundler | bundler | — | — |
| bundler | bundler | — | — |
| bundler | bundler | — | — |
| bundler | bundler | — | — |
| bundler | bundler | — | — |
| bundler | bundler | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
ghsa5.0MEDIUM
osv5.0MEDIUM
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Bundler allows attacker to inject arbitrary code via secondary Gem source
osv·2022-05-14·CVSS 5.0
CVE-2016-7954 [MEDIUM] Bundler allows attacker to inject arbitrary code via secondary Gem source
Bundler allows attacker to inject arbitrary code via secondary Gem source
Bundler 1.x might allow remote attackers to inject arbitrary Ruby code into an application by leveraging a gem name collision on a secondary source. NOTE: this might overlap CVE-2013-0334.
GHSA
Bundler allows attacker to inject arbitrary code via secondary Gem source
ghsa·2022-05-14·CVSS 5.0
CVE-2016-7954 [MEDIUM] CWE-94 Bundler allows attacker to inject arbitrary code via secondary Gem source
Bundler allows attacker to inject arbitrary code via secondary Gem source
Bundler 1.x might allow remote attackers to inject arbitrary Ruby code into an application by leveraging a gem name collision on a secondary source. NOTE: this might overlap CVE-2013-0334.
GHSA
Bundler may install gems from a different source than expected
ghsa·2022-05-05
CVE-2013-0334 [MEDIUM] CWE-20 Bundler may install gems from a different source than expected
Bundler may install gems from a different source than expected
Bundler before 1.7, when multiple top-level source lines are used, allows remote attackers to install arbitrary gems by creating a gem with the same name as another gem in a different source.
OSV
Bundler may install gems from a different source than expected
osv·2022-05-05
CVE-2013-0334 [MEDIUM] Bundler may install gems from a different source than expected
Bundler may install gems from a different source than expected
Bundler before 1.7, when multiple top-level source lines are used, allows remote attackers to install arbitrary gems by creating a gem with the same name as another gem in a different source.
OSV
CVE-2016-7954: Bundler 1
osv·2016-12-22·CVSS 5.0
CVE-2016-7954 [MEDIUM] CVE-2016-7954: Bundler 1
Bundler 1.x might allow remote attackers to inject arbitrary Ruby code into an application by leveraging a gem name collision on a secondary source. NOTE: this might overlap CVE-2013-0334.
OSV
CVE-2013-0334: Bundler before 1
osv·2014-10-31·CVSS 5.0
CVE-2013-0334 [MEDIUM] CVE-2013-0334: Bundler before 1
Bundler before 1.7, when multiple top-level source lines are used, allows remote attackers to install arbitrary gems by creating a gem with the same name as another gem in a different source.
Red Hat
rubygem-bundler: Code execution via gem name collision in bundler
vendor_redhat·2016-10-04·CVSS 5.0
CVE-2016-7954 [MEDIUM] CWE-94 rubygem-bundler: Code execution via gem name collision in bundler
rubygem-bundler: Code execution via gem name collision in bundler
Bundler 1.x might allow remote attackers to inject arbitrary Ruby code into an application by leveraging a gem name collision on a secondary source. NOTE: this might overlap CVE-2013-0334.
Statement: Red Hat Product Security has rated this issue as having Moderate security impact. This issue is not currently planned to be addressed in future updates. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.
Package: rubygem-bundler (Red Hat Enterprise Linux 7) - Will not fix
Package: rubygem-bundler (Red Hat Enterprise Linux OpenStack Platform 5 (Icehouse)) - Will not fix
Package: rubygem-bundler (Red Hat Enterprise Linux OpenStack Platform 6 (Jun
Red Hat
rubygem-bundler: 'bundle install' may install a gem from a source other than expected
vendor_redhat·2014-08-14·CVSS 5.0
CVE-2013-0334 [MEDIUM] CWE-345 rubygem-bundler: 'bundle install' may install a gem from a source other than expected
rubygem-bundler: 'bundle install' may install a gem from a source other than expected
Bundler before 1.7, when multiple top-level source lines are used, allows remote attackers to install arbitrary gems by creating a gem with the same name as another gem in a different source.
A flaw was found in the way Bundler handled gems available from multiple sources. An attacker with access to one of the sources could create a malicious gem with the same name, which they could then use to trick a user into installing, potentially resulting in execution of code from the attacker-supplied malicious gem.
Package: ruby193-rubygem-bundler (CloudForms Management Engine 5) - Will not fix
Package: ruby193-rubygem-bundler (OpenShift Enterprise 1) - Will not fix
Package: rubygem-bundler (OpenShift Enterp
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2013-0334 rubygem-bundler: 'bundle install' may install a gem from a source other than expected [fedora-all]
bugzilla·2014-09-25·CVSS 5.0
CVE-2013-0334 [MEDIUM] CVE-2013-0334 rubygem-bundler: 'bundle install' may install a gem from a source other than expected [fedora-all]
CVE-2013-0334 rubygem-bundler: 'bundle install' may install a gem from a source other than expected [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affe
Bugzilla
CVE-2013-0334 rubygem-bundler: 'bundle install' may install a gem from a source other than expected
bugzilla·2014-09-25·CVSS 5.0
CVE-2013-0334 [MEDIUM] CVE-2013-0334 rubygem-bundler: 'bundle install' may install a gem from a source other than expected
CVE-2013-0334 rubygem-bundler: 'bundle install' may install a gem from a source other than expected
The 1.7.0 release of Bundler fixes an issue where a gem may be installed from a source other than expected, if the gem file had multiple, top-level source lines. This could potentially lead to a malicious gem file being installed.
From the upstream advisory:
""
Any Gemfile with multiple top-level source lines cannot reliably control the gem server that a particular gem is fetched from. As a result, Bundler might install the wrong gem if more than one source provides a gem with the same name.
This is especially possible in the case of Github's legacy gem server, hosted at gems.github.com. An attacker might create a malicious gem on Rubygems.org with the same name as a commonly-used Github
http://bundler.io/blog/2014/08/14/bundler-may-install-gems-from-a-different-source-than-expected-cve-2013-0334.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2014-October/140609.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2014-October/140654.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2014-October/140655.htmlhttp://lists.opensuse.org/opensuse-updates/2015-03/msg00092.htmlhttp://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.htmlhttp://www.securityfocus.com/bid/70099https://security.gentoo.org/glsa/201609-02http://bundler.io/blog/2014/08/14/bundler-may-install-gems-from-a-different-source-than-expected-cve-2013-0334.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2014-October/140609.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2014-October/140654.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2014-October/140655.htmlhttp://lists.opensuse.org/opensuse-updates/2015-03/msg00092.htmlhttp://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.htmlhttp://www.securityfocus.com/bid/70099https://security.gentoo.org/glsa/201609-02
2014-10-31
Published