CVE-2013-0334

EPSS 0.50%

Bundler may install gems from a different source than expected

Published: 5/5/2022Modified: 12/6/2024
Also known as:GHSA-49jx-9cmc-xjxm

Description

Bundler before 1.7, when multiple top-level source lines are used, allows remote attackers to install arbitrary gems by creating a gem with the same name as another gem in a different source.

Affected packages (1)

References (11)