PT-2022-23161 · Unknown · Rubygems.Org

Segiddins

·

Published

2022-09-07

·

Updated

2022-09-12

·

CVE-2022-36073

CVSS v3.1

8.3

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L
Name of the Vulnerable Software and Affected Versions RubyGems.org (affected versions not specified)
Description A bug in the password and email change confirmation code allowed an attacker to change their RubyGems.org account's email to an unowned email address. This could enable the attacker to save API keys for that account. When a legitimate user attempts to create an account with their email and has to reset the password to gain access, the attacker could then be able to publish and yank versions of those gems.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Authentication

Weakness Enumeration

Related Identifiers

CVE-2022-36073
GHSA-8QPF-WF2P-25VG

Affected Products

Rubygems.Org