Debian Rubygems vulnerabilities
28 known vulnerabilities affecting debian/rubygems.
Total CVEs
28
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH13MEDIUM8LOW5
Vulnerabilities
Page 2 of 2
CVE-2023-28755P4MEDIUMCVSS 5.3fixed in jruby 9.4.5.0+ds-1 (forky)2023
CVE-2023-28755 [MEDIUM] CVE-2023-28755: jruby - A ReDoS issue was discovered in the URI component through 0.12.0 in Ruby through...
A ReDoS issue was discovered in the URI component through 0.12.0 in Ruby through 3.2.1. The URI parser mishandles invalid URLs that have specific characters. It causes an increase in execution time for parsing strings to URI objects. The fixed versions are 0.12.1, 0.11.1, 0.10.2 and 0.10.0.1.
Scope: local
bookworm: open
forky: resolved (fixed in 9.4.5.0+ds-1)
sid: r
debian
CVE-2018-1000078P4MEDIUMCVSS 6.1fixed in jruby 9.1.17.0-1 (bookworm)2018
CVE-2018-1000078 [MEDIUM] CVE-2018-1000078: jruby - RubyGems version Ruby 2.2 series: 2.2.9 and earlier, Ruby 2.3 series: 2.3.6 and ...
RubyGems version Ruby 2.2 series: 2.2.9 and earlier, Ruby 2.3 series: 2.3.6 and earlier, Ruby 2.4 series: 2.4.3 and earlier, Ruby 2.5 series: 2.5.0 and earlier, prior to trunk revision 62422 contains a Cross Site Scripting (XSS) vulnerability in gem server display of homepage attribute that can result in XSS. This attack appear to be exploitable via the victim m
debian
CVE-2023-36617P4LOWCVSS 5.3fixed in ruby2.7 2.7.4-1+deb11u2 (bullseye)2023
CVE-2023-36617 [MEDIUM] CVE-2023-36617: jruby - A ReDoS issue was discovered in the URI component before 0.12.2 for Ruby. The UR...
A ReDoS issue was discovered in the URI component before 0.12.2 for Ruby. The URI parser mishandles invalid URLs that have specific characters. There is an increase in execution time for parsing strings to URI objects with rfc2396_parser.rb and rfc3986_parser.rb. NOTE: this issue exists becuse of an incomplete fix for CVE-2023-28755. Version 0.10.3 is also a fixed v
debian
CVE-2025-27221P4LOWCVSS 3.2fixed in ruby2.7 2.7.4-1+deb11u5 (bullseye)2025
CVE-2025-27221 [LOW] CVE-2025-27221: ruby2.7 - In the URI gem before 1.0.3 for Ruby, the URI handling methods (URI.join, URI#me...
In the URI gem before 1.0.3 for Ruby, the URI handling methods (URI.join, URI#merge, URI#+) have an inadvertent leakage of authentication credentials because userinfo is retained even after changing the host.
Scope: local
bullseye: resolved (fixed in 2.7.4-1+deb11u5)
debian
CVE-2012-2125P4MEDIUMCVSS 5.8fixed in rubygems 1.8.24-1 (bookworm)2012
CVE-2012-2125 [MEDIUM] CVE-2012-2125: rubygems - RubyGems before 1.8.23 can redirect HTTPS connections to HTTP, which makes it ea...
RubyGems before 1.8.23 can redirect HTTPS connections to HTTP, which makes it easier for remote attackers to observe or modify a gem during installation via a man-in-the-middle attack.
Scope: local
bookworm: resolved (fixed in 1.8.24-1)
bullseye: resolved (fixed in 1.8.24-1)
forky: resolved (fixed in 1.8.24-1)
sid: resolved (fixed in 1.8.24-1)
trixie: resolved (fix
debian
CVE-2013-4287P4LOWCVSS 4.3fixed in rubygems 3.2.0~rc.1-1 (bookworm)2013
CVE-2013-4287 [MEDIUM] CVE-2013-4287: rubygems - Algorithmic complexity vulnerability in Gem::Version::VERSION_PATTERN in lib/rub...
Algorithmic complexity vulnerability in Gem::Version::VERSION_PATTERN in lib/rubygems/version.rb in RubyGems before 1.8.23.1, 1.8.24 through 1.8.25, 2.0.x before 2.0.8, and 2.1.x before 2.1.0, as used in Ruby 1.9.0 through 2.0.0p247, allows remote attackers to cause a denial of service (CPU consumption) via a crafted gem version that triggers a large amount of back
debian
CVE-2012-2126P4MEDIUMCVSS 4.3fixed in rubygems 1.8.24-1 (bookworm)2012
CVE-2012-2126 [MEDIUM] CVE-2012-2126: rubygems - RubyGems before 1.8.23 does not verify an SSL certificate, which allows remote a...
RubyGems before 1.8.23 does not verify an SSL certificate, which allows remote attackers to modify a gem during installation via a man-in-the-middle attack.
Scope: local
bookworm: resolved (fixed in 1.8.24-1)
bullseye: resolved (fixed in 1.8.24-1)
forky: resolved (fixed in 1.8.24-1)
sid: resolved (fixed in 1.8.24-1)
trixie: resolved (fixed in 1.8.24-1)
debian
CVE-2013-4363P4LOWCVSS 4.3fixed in rubygems 3.2.0~rc.1-1 (bookworm)2013
CVE-2013-4363 [MEDIUM] CVE-2013-4363: rubygems - Algorithmic complexity vulnerability in Gem::Version::ANCHORED_VERSION_PATTERN i...
Algorithmic complexity vulnerability in Gem::Version::ANCHORED_VERSION_PATTERN in lib/rubygems/version.rb in RubyGems before 1.8.23.2, 1.8.24 through 1.8.26, 2.0.x before 2.0.10, and 2.1.x before 2.1.5, as used in Ruby 1.9.0 through 2.0.0p247, allows remote attackers to cause a denial of service (CPU consumption) via a crafted gem version that triggers a large amou
debian
← Previous2 / 2