Debian Rubygems vulnerabilities
28 known vulnerabilities affecting debian/rubygems.
Total CVEs
28
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH13MEDIUM8LOW5
Vulnerabilities
Page 1 of 2
CVE-2017-0901P2HIGHCVSS 7.5PoCfixed in rubygems 3.2.0~rc.1-1 (bookworm)2017
CVE-2017-0901 [HIGH] CVE-2017-0901: rubygems - RubyGems version 2.6.12 and earlier fails to validate specification names, allow...
RubyGems version 2.6.12 and earlier fails to validate specification names, allowing a maliciously crafted gem to potentially overwrite any file on the filesystem.
Scope: local
bookworm: resolved (fixed in 3.2.0~rc.1-1)
bullseye: resolved (fixed in 3.2.0~rc.1-1)
forky: resolved (fixed in 3.2.0~rc.1-1)
sid: resolved (fixed in 3.2.0~rc.1-1)
trixie: resolved (fixed in 3.
debian
CVE-2017-0903P2CRITICALCVSS 9.8fixed in rubygems 3.2.0~rc.1-1 (bookworm)2017
CVE-2017-0903 [CRITICAL] CVE-2017-0903: rubygems - RubyGems versions between 2.0.0 and 2.6.13 are vulnerable to a possible remote c...
RubyGems versions between 2.0.0 and 2.6.13 are vulnerable to a possible remote code execution vulnerability. YAML deserialization of gem specifications can bypass class white lists. Specially crafted serialized objects can possibly be used to escalate to remote code execution.
Scope: local
bookworm: resolved (fixed in 3.2.0~rc.1-1)
bullseye: resolved (fixed in 3.
debian
CVE-2017-0899P3LOWCVSS 9.8fixed in rubygems 3.2.0~rc.1-1 (bookworm)2017
CVE-2017-0899 [CRITICAL] CVE-2017-0899: rubygems - RubyGems version 2.6.12 and earlier is vulnerable to maliciously crafted gem spe...
RubyGems version 2.6.12 and earlier is vulnerable to maliciously crafted gem specifications that include terminal escape characters. Printing the gem specification would execute terminal escape sequences.
Scope: local
bookworm: resolved (fixed in 3.2.0~rc.1-1)
bullseye: resolved (fixed in 3.2.0~rc.1-1)
forky: resolved (fixed in 3.2.0~rc.1-1)
sid: resolved (fixed
debian
CVE-2018-1000076P3CRITICALCVSS 9.8fixed in jruby 9.1.17.0-1 (bookworm)2018
CVE-2018-1000076 [CRITICAL] CVE-2018-1000076: jruby - RubyGems version Ruby 2.2 series: 2.2.9 and earlier, Ruby 2.3 series: 2.3.6 and ...
RubyGems version Ruby 2.2 series: 2.2.9 and earlier, Ruby 2.3 series: 2.3.6 and earlier, Ruby 2.4 series: 2.4.3 and earlier, Ruby 2.5 series: 2.5.0 and earlier, prior to trunk revision 62422 contains a Improper Verification of Cryptographic Signature vulnerability in package.rb that can result in a mis-signed gem could be installed, as the tarball would contai
debian
CVE-2020-36327P3HIGHCVSS 8.8fixed in rubygems 3.3.5-1 (bookworm)2020
CVE-2020-36327 [HIGH] CVE-2020-36327: rubygems - Bundler 1.16.0 through 2.2.9 and 2.2.11 through 2.2.16 sometimes chooses a depen...
Bundler 1.16.0 through 2.2.9 and 2.2.11 through 2.2.16 sometimes chooses a dependency source based on the highest gem version number, which means that a rogue gem found at a public source may be chosen, even if the intended choice was a private gem that is a dependency of another private gem that is explicitly depended on by the application. NOTE: it is not correct
debian
CVE-2017-0902P3HIGHCVSS 8.1fixed in rubygems 3.2.0~rc.1-1 (bookworm)2017
CVE-2017-0902 [HIGH] CVE-2017-0902: rubygems - RubyGems version 2.6.12 and earlier is vulnerable to a DNS hijacking vulnerabili...
RubyGems version 2.6.12 and earlier is vulnerable to a DNS hijacking vulnerability that allows a MITM attacker to force the RubyGems client to download and install gems from a server that the attacker controls.
Scope: local
bookworm: resolved (fixed in 3.2.0~rc.1-1)
bullseye: resolved (fixed in 3.2.0~rc.1-1)
forky: resolved (fixed in 3.2.0~rc.1-1)
sid: resolved (fixe
debian
CVE-2019-8324P3HIGHCVSS 8.8fixed in jruby 9.1.17.0-3 (bookworm)2019
CVE-2019-8324 [HIGH] CVE-2019-8324: jruby - An issue was discovered in RubyGems 2.6 and later through 3.0.2. A crafted gem w...
An issue was discovered in RubyGems 2.6 and later through 3.0.2. A crafted gem with a multi-line name is not handled correctly. Therefore, an attacker could inject arbitrary code to the stub line of gemspec, which is eval-ed by code in ensure_loadable_spec during the preinstall check.
Scope: local
bookworm: resolved (fixed in 9.1.17.0-3)
forky: resolved (fixed in 9.1.17
debian
CVE-2019-8320P3HIGHCVSS 7.4fixed in jruby 9.1.17.0-3 (bookworm)2019
CVE-2019-8320 [HIGH] CVE-2019-8320: jruby - A Directory Traversal issue was discovered in RubyGems 2.7.6 and later through 3...
A Directory Traversal issue was discovered in RubyGems 2.7.6 and later through 3.0.2. Before making new directories or touching files (which now include path-checking code for symlinks), it would delete the target destination. If that destination was hidden behind a symlink, a malicious gem could delete arbitrary files on the user's machine, presuming the attacker could
debian
CVE-2018-1000073P3HIGHCVSS 7.5fixed in jruby 9.1.17.0-2.1 (bookworm)2018
CVE-2018-1000073 [HIGH] CVE-2018-1000073: jruby - RubyGems version Ruby 2.2 series: 2.2.9 and earlier, Ruby 2.3 series: 2.3.6 and ...
RubyGems version Ruby 2.2 series: 2.2.9 and earlier, Ruby 2.3 series: 2.3.6 and earlier, Ruby 2.4 series: 2.4.3 and earlier, Ruby 2.5 series: 2.5.0 and earlier, prior to trunk revision 62422 contains a Directory Traversal vulnerability in install_location function of package.rb that can result in path traversal when writing to a symlinked basedir outside of the ro
debian
CVE-2019-8322P3HIGHCVSS 7.5fixed in jruby 9.1.17.0-3 (bookworm)2019
CVE-2019-8322 [HIGH] CVE-2019-8322: jruby - An issue was discovered in RubyGems 2.6 and later through 3.0.2. The gem owner c...
An issue was discovered in RubyGems 2.6 and later through 3.0.2. The gem owner command outputs the contents of the API response directly to stdout. Therefore, if the response is crafted, escape sequence injection may occur.
Scope: local
bookworm: resolved (fixed in 9.1.17.0-3)
forky: resolved (fixed in 9.1.17.0-3)
sid: resolved (fixed in 9.1.17.0-3)
trixie: resolved (fi
debian
CVE-2019-8323P3HIGHCVSS 7.5fixed in jruby 9.1.17.0-3 (bookworm)2019
CVE-2019-8323 [HIGH] CVE-2019-8323: jruby - An issue was discovered in RubyGems 2.6 and later through 3.0.2. Gem::GemcutterU...
An issue was discovered in RubyGems 2.6 and later through 3.0.2. Gem::GemcutterUtilities#with_response may output the API response to stdout as it is. Therefore, if the API side modifies the response, escape sequence injection may occur.
Scope: local
bookworm: resolved (fixed in 9.1.17.0-3)
forky: resolved (fixed in 9.1.17.0-3)
sid: resolved (fixed in 9.1.17.0-3)
trixie
debian
CVE-2017-0900P3HIGHCVSS 7.5fixed in rubygems 3.2.0~rc.1-1 (bookworm)2017
CVE-2017-0900 [HIGH] CVE-2017-0900: rubygems - RubyGems version 2.6.12 and earlier is vulnerable to maliciously crafted gem spe...
RubyGems version 2.6.12 and earlier is vulnerable to maliciously crafted gem specifications to cause a denial of service attack against RubyGems clients who have issued a `query` command.
Scope: local
bookworm: resolved (fixed in 3.2.0~rc.1-1)
bullseye: resolved (fixed in 3.2.0~rc.1-1)
forky: resolved (fixed in 3.2.0~rc.1-1)
sid: resolved (fixed in 3.2.0~rc.1-1)
trix
debian
CVE-2018-1000074P3HIGHCVSS 7.8fixed in jruby 9.1.17.0-1 (bookworm)2018
CVE-2018-1000074 [HIGH] CVE-2018-1000074: jruby - RubyGems version Ruby 2.2 series: 2.2.9 and earlier, Ruby 2.3 series: 2.3.6 and ...
RubyGems version Ruby 2.2 series: 2.2.9 and earlier, Ruby 2.3 series: 2.3.6 and earlier, Ruby 2.4 series: 2.4.3 and earlier, Ruby 2.5 series: 2.5.0 and earlier, prior to trunk revision 62422 contains a Deserialization of Untrusted Data vulnerability in owner command that can result in code execution. This attack appear to be exploitable via victim must run the `ge
debian
CVE-2018-1000075P3HIGHCVSS 7.5fixed in jruby 9.1.17.0-1 (bookworm)2018
CVE-2018-1000075 [HIGH] CVE-2018-1000075: jruby - RubyGems version Ruby 2.2 series: 2.2.9 and earlier, Ruby 2.3 series: 2.3.6 and ...
RubyGems version Ruby 2.2 series: 2.2.9 and earlier, Ruby 2.3 series: 2.3.6 and earlier, Ruby 2.4 series: 2.4.3 and earlier, Ruby 2.5 series: 2.5.0 and earlier, prior to trunk revision 62422 contains a infinite loop caused by negative size vulnerability in ruby gem package tar header that can result in a negative size could cause an infinite loop.. This vulnerabil
debian
CVE-2019-8325P3HIGHCVSS 7.5fixed in jruby 9.1.17.0-3 (bookworm)2019
CVE-2019-8325 [HIGH] CVE-2019-8325: jruby - An issue was discovered in RubyGems 2.6 and later through 3.0.2. Since Gem::Comm...
An issue was discovered in RubyGems 2.6 and later through 3.0.2. Since Gem::CommandManager#run calls alert_error without escaping, escape sequence injection is possible. (There are many ways to cause an error.)
Scope: local
bookworm: resolved (fixed in 9.1.17.0-3)
forky: resolved (fixed in 9.1.17.0-3)
sid: resolved (fixed in 9.1.17.0-3)
trixie: resolved (fixed in 9.1.17
debian
CVE-2019-8321P3HIGHCVSS 7.5fixed in jruby 9.1.17.0-3 (bookworm)2019
CVE-2019-8321 [HIGH] CVE-2019-8321: jruby - An issue was discovered in RubyGems 2.6 and later through 3.0.2. Since Gem::User...
An issue was discovered in RubyGems 2.6 and later through 3.0.2. Since Gem::UserInteraction#verbose calls say without escaping, escape sequence injection is possible.
Scope: local
bookworm: resolved (fixed in 9.1.17.0-3)
forky: resolved (fixed in 9.1.17.0-3)
sid: resolved (fixed in 9.1.17.0-3)
trixie: resolved (fixed in 9.1.17.0-3)
debian
CVE-2021-43809P3MEDIUMCVSS 6.7fixed in rubygems 3.3.5-1 (bookworm)2021
CVE-2021-43809 [MEDIUM] CVE-2021-43809: rubygems - `Bundler` is a package for managing application dependencies in Ruby. In `bundle...
`Bundler` is a package for managing application dependencies in Ruby. In `bundler` versions before 2.2.33, when working with untrusted and apparently harmless `Gemfile`'s, it is not expected that they lead to execution of external code, unless that's explicit in the ruby code inside the `Gemfile` itself. However, if the `Gemfile` includes `gem` entries that use t
debian
CVE-2015-3900P3MEDIUMCVSS 5.0fixed in jruby 1.7.20.1-2 (bookworm)2015
CVE-2015-3900 [MEDIUM] CVE-2015-3900: jruby - RubyGems 2.0.x before 2.0.16, 2.2.x before 2.2.4, and 2.4.x before 2.4.7 does no...
RubyGems 2.0.x before 2.0.16, 2.2.x before 2.2.4, and 2.4.x before 2.4.7 does not validate the hostname when fetching gems or making API requests, which allows remote attackers to redirect requests to arbitrary domains via a crafted DNS SRV record, aka a "DNS hijack attack."
Scope: local
bookworm: resolved (fixed in 1.7.20.1-2)
forky: resolved (fixed in 1.7.20.1-2)
si
debian
CVE-2018-1000077P4MEDIUMCVSS 5.3fixed in jruby 9.1.17.0-1 (bookworm)2018
CVE-2018-1000077 [MEDIUM] CVE-2018-1000077: jruby - RubyGems version Ruby 2.2 series: 2.2.9 and earlier, Ruby 2.3 series: 2.3.6 and ...
RubyGems version Ruby 2.2 series: 2.2.9 and earlier, Ruby 2.3 series: 2.3.6 and earlier, Ruby 2.4 series: 2.4.3 and earlier, Ruby 2.5 series: 2.5.0 and earlier, prior to trunk revision 62422 contains a Improper Input Validation vulnerability in ruby gems specification homepage attribute that can result in a malicious gem could set an invalid homepage URL. This v
debian
CVE-2018-1000079P4MEDIUMCVSS 5.5fixed in jruby 9.1.17.0-1 (bookworm)2018
CVE-2018-1000079 [MEDIUM] CVE-2018-1000079: jruby - RubyGems version Ruby 2.2 series: 2.2.9 and earlier, Ruby 2.3 series: 2.3.6 and ...
RubyGems version Ruby 2.2 series: 2.2.9 and earlier, Ruby 2.3 series: 2.3.6 and earlier, Ruby 2.4 series: 2.4.3 and earlier, Ruby 2.5 series: 2.5.0 and earlier, prior to trunk revision 62422 contains a Directory Traversal vulnerability in gem installation that can result in the gem could write to arbitrary filesystem locations during installation. This attack ap
debian
1 / 2Next →