CVE-2020-36327
published 2021-04-29CVE-2020-36327: Bundler 1.16.0 through 2.2.9 and 2.2.11 through 2.2.16 sometimes chooses a dependency source based on the highest gem version number, which means that a rogue…
PriorityP349high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
6.31%
92.8th percentile
Bundler 1.16.0 through 2.2.9 and 2.2.11 through 2.2.16 sometimes chooses a dependency source based on the highest gem version number, which means that a rogue gem found at a public source may be chosen, even if the intended choice was a private gem that is a dependency of another private gem that is explicitly depended on by the application. NOTE: it is not correct to use CVE-2021-24105 for every "Dependency Confusion" issue in every product.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| bundler | bundler | >= 1.16.0 < 2.2.10 | 2.2.10 |
| bundler | bundler | >= 1.16.0 < 2.2.10 | 2.2.10 |
| bundler | bundler | >= 2.2.11 < 2.2.18 | 2.2.18 |
| bundler | bundler | 2.2.11 – 2.2.16 | — |
| debian | rubygems | < rubygems 3.3.5-1 (bookworm) | rubygems 3.3.5-1 (bookworm) |
| fedoraproject | fedora | — | — |
| rubygems | rubygems | >= 0 < 3.3.5-1 | 3.3.5-1 |
| rubygems | rubygems | >= 0 < 3.3.5-1 | 3.3.5-1 |
| rubygems | rubygems | >= 0 < 3.3.5-1 | 3.3.5-1 |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
osv8.8HIGH
vendor_debian8.8HIGH
vendor_redhat8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
rubygem-bundler: Dependencies of gems with explicit source may be installed from a different source
vendor_redhat·2021-02-09·CVSS 8.8
CVE-2020-36327 [HIGH] CWE-494 rubygem-bundler: Dependencies of gems with explicit source may be installed from a different source
rubygem-bundler: Dependencies of gems with explicit source may be installed from a different source
Bundler 1.16.0 through 2.2.9 and 2.2.11 through 2.2.16 sometimes chooses a dependency source based on the highest gem version number, which means that a rogue gem found at a public source may be chosen, even if the intended choice was a private gem that is a dependency of another private gem that is explicitly depended on by the application. NOTE: it is not correct to use CVE-2021-24105 for every "Dependency Confusion" issue in every product.
A flaw was found in the way Bundler determined the source repository when installing dependencies of source-restricted gem packages. In configurations that use multiple gem repositories and explicitly define from which source repository certain gems a
Debian
CVE-2020-36327: rubygems - Bundler 1.16.0 through 2.2.9 and 2.2.11 through 2.2.16 sometimes chooses a depen...
vendor_debian·2020·CVSS 8.8
CVE-2020-36327 [HIGH] CVE-2020-36327: rubygems - Bundler 1.16.0 through 2.2.9 and 2.2.11 through 2.2.16 sometimes chooses a depen...
Bundler 1.16.0 through 2.2.9 and 2.2.11 through 2.2.16 sometimes chooses a dependency source based on the highest gem version number, which means that a rogue gem found at a public source may be chosen, even if the intended choice was a private gem that is a dependency of another private gem that is explicitly depended on by the application. NOTE: it is not correct to use CVE-2021-24105 for every "Dependency Confusion" issue in every product.
Scope: local
bookworm: resolved (fixed in 3.3.5-1)
bullseye: open
forky: resolved (fixed in 3.3.5-1)
sid: resolved (fixed in 3.3.5-1)
trixie: resolved (fixed in 3.3.5-1)
OSV
Dependency Confusion in Bundler
osv·2021-05-24
CVE-2020-36327 [HIGH] Dependency Confusion in Bundler
Dependency Confusion in Bundler
Bundler 1.16.0 through 2.2.9 and 2.2.11 through 2.2.17 sometimes chooses a dependency source based on the highest gem version number, which means that a rogue gem found at a public source may be chosen, even if the intended choice was a private gem that is a dependency of another private gem that is explicitly depended on by the application.
GHSA
Dependency Confusion in Bundler
ghsa·2021-05-24
CVE-2020-36327 [HIGH] Dependency Confusion in Bundler
Dependency Confusion in Bundler
Bundler 1.16.0 through 2.2.9 and 2.2.11 through 2.2.17 sometimes chooses a dependency source based on the highest gem version number, which means that a rogue gem found at a public source may be chosen, even if the intended choice was a private gem that is a dependency of another private gem that is explicitly depended on by the application.
OSV
CVE-2020-36327: Bundler 1
osv·2021-04-29·CVSS 8.8
CVE-2020-36327 [HIGH] CVE-2020-36327: Bundler 1
Bundler 1.16.0 through 2.2.9 and 2.2.11 through 2.2.16 sometimes chooses a dependency source based on the highest gem version number, which means that a rogue gem found at a public source may be chosen, even if the intended choice was a private gem that is a dependency of another private gem that is explicitly depended on by the application. NOTE: it is not correct to use CVE-2021-24105 for every "Dependency Confusion" issue in every product.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://bundler.io/blog/2021/02/15/a-more-secure-bundler-we-fixed-our-source-priorities.htmlhttps://github.com/rubygems/rubygems/issues/3982https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MWXHK5UUHVSHF7HTHMX6JY3WXDVNIHSL/https://mensfeld.pl/2021/02/rubygems-dependency-confusion-attack-side-of-things/https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2021-24105https://www.zofrex.com/blog/2021/04/29/bundler-still-vulnerable-dependency-confusion-cve-2020-36327/https://bundler.io/blog/2021/02/15/a-more-secure-bundler-we-fixed-our-source-priorities.htmlhttps://github.com/rubygems/rubygems/issues/3982https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MWXHK5UUHVSHF7HTHMX6JY3WXDVNIHSL/https://mensfeld.pl/2021/02/rubygems-dependency-confusion-attack-side-of-things/https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2021-24105https://www.zofrex.com/blog/2021/04/29/bundler-still-vulnerable-dependency-confusion-cve-2020-36327/
2021-04-29
Published