[ASA-202106-14] ruby-bundler: insufficient validation
diabonas at archlinux.org
Thu Jun 3 08:44:18 UTC 2021
Arch Linux Security Advisory ASA-202106-14
Date : 2021-06-01
CVE-ID : CVE-2020-36327
Package : ruby-bundler
Type : insufficient validation
Remote : Yes
Link : https://security.archlinux.org/AVG-1891
The package ruby-bundler before version 2.2.18-1 is vulnerable to
Upgrade to 2.2.18-1.
# pacman -Syu "ruby-bundler>=2.2.18-1"
The problem has been fixed upstream in version 2.2.18.
Bundler 1.16.0 through 2.2.9 and 2.2.11 through 2.2.17 sometimes
chooses a dependency source based on the highest gem version number,
which means that a rogue gem found at a public source may be chosen,
even if the intended choice was a private gem that is a dependency of
another private gem that is explicitly depended on by the application.
A remote attacker could replace a private gem in a project with a
public gem under their control with a higher version number.
-------------- next part --------------
A non-text attachment was scrubbed...
Size: 833 bytes
Desc: not available
More information about the arch-security