Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Andreas Loupasakis

#48714de 53,638
5CVSS total
Vulnerabilidades · 1
PT-2014-2451
5.0
2014-10-31
Ruby · Bundler · CVE-2013-0334
**Name of the Vulnerable Software and Affected Versions** Bundler versions prior to 1.7 **Description** The issue allows remote attackers to install arbitrary gems by creating a gem with the same name as another gem in a different source when multiple top-level source lines are used. **Recommendations** For versions prior to 1.7, update to version 1.7 or later to resolve the issue. As a temporary workaround, consider restricting the use of multiple top-level source lines to minimize the risk of exploitation.