rubygems kayıtları
rubygems üreticisine ait 35 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 6
- Düzeltme kaydı olan
- %80
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-20 Improper Input Validation6
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')4
- CWE-94 Improper Control of Generation of Code ('Code Injection')4
- CWE-310 Cryptographic Issues3
- CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')3
- CWE-287 Improper Authentication2
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWEBug bounty kapsamı
Ürünün üreticisi herkese açık bir programda görünüyor. Eşleşme ad üzerinden yapıldı; kapsam metnini programda doğrulayın.
Tüm kayıtlar
35 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
44Planlayın | CVE-2017-0903İstismar yok | RubyGems versions between 2.0.0 and 2.6.13 are vulnerable to a possible remote code execution vulnerability.rubygems · rubygems · CWE-502 | Kritik9,8 | — | %15,9 | 11 Eki 2017 |
42Planlayın | CVE-2017-0899İstismar yok | RubyGems version 2.6.12 and earlier is vulnerable to maliciously crafted gem specifications that include terminal escape characters.rubygems · rubygems · CWE-150 | Kritik9,8 | — | %10,8 | 31 Ağu 2017 |
40Planlayın | CVE-2018-1000076İstismar yok | RubyGems version Ruby 2.2 series: 2.2.9 and earlier, Ruby 2.3 series: 2.3.6 and earlier, Ruby 2.4 series: 2.4.3 and earlier, Ruby 2.5 seriesrubygems · rubygems · CWE-347 | Kritik9,8 | — | %2,9 | 13 Mar 2018 |
39İzleyin | CVE-2017-0901Kavram kanıtı | RubyGems version 2.6.12 and earlier fails to validate specification names, allowing a maliciously crafted gem to potentially overwrite any frubygems · rubygems · CWE-22 | Yüksek7,5 | — | %28,7 | 31 Ağu 2017 |
39İzleyin | CVE-2024-21654İstismar yok | rubygems.org MFA Bypass through password reset function could allow account takeoverrubygems · rubygems.org · CWE-287 | Kritik9,8 | — | %0,5 | 12 Oca 2024 |
36İzleyin | CVE-2019-8324İstismar yok | An issue was discovered in RubyGems 2.6 and later through 3.0.2.rubygems · rubygems · CWE-94 | Yüksek8,8 | — | %3,2 | 17 Haz 2019 |
35İzleyin | CVE-2022-36073İstismar yok | RubyGems allows creation of users with arbitrary unverified emailsrubygems · rubygems · CWE-287 | Yüksek8,8 | — | %1,0 | 7 Eyl 2022 |
34İzleyin | CVE-2013-0269Kavram kanıtı | The JSON gem before 1.5.5, 1.6.x before 1.6.8, and 1.7.x before 1.7.7 for Ruby allows remote attackers to cause a denial of service (resourcrubygems · json gem · CWE-20 | Yüksek7,5 | — | %13,4 | 12 Şub 2013 |
33İzleyin | CVE-2017-0902İstismar yok | RubyGems version 2.6.12 and earlier is vulnerable to a DNS hijacking vulnerability that allows a MITM attacker to force the RubyGems client rubygems · rubygems · CWE-350 | Yüksek8,1 | — | %4,7 | 31 Ağu 2017 |
32İzleyin | CVE-2017-0900İstismar yok | RubyGems version 2.6.12 and earlier is vulnerable to maliciously crafted gem specifications to cause a denial of service attack against Rubyrubygems · rubygems · CWE-20 | Yüksek7,5 | — | %8,3 | 31 Ağu 2017 |
32İzleyin | CVE-2018-1000074İstismar yok | RubyGems version Ruby 2.2 series: 2.2.9 and earlier, Ruby 2.3 series: 2.3.6 and earlier, Ruby 2.4 series: 2.4.3 and earlier, Ruby 2.5 seriesrubygems · rubygems · CWE-502 | Yüksek7,8 | — | %2,9 | 13 Mar 2018 |
31İzleyin | CVE-2018-1000073İstismar yok | RubyGems version Ruby 2.2 series: 2.2.9 and earlier, Ruby 2.3 series: 2.3.6 and earlier, Ruby 2.4 series: 2.4.3 and earlier, Ruby 2.5 seriesrubygems · rubygems · CWE-59 | Yüksek7,5 | — | %4,9 | 13 Mar 2018 |
31İzleyin | CVE-2018-1000075İstismar yok | RubyGems version Ruby 2.2 series: 2.2.9 and earlier, Ruby 2.3 series: 2.3.6 and earlier, Ruby 2.4 series: 2.4.3 and earlier, Ruby 2.5 seriesrubygems · rubygems · CWE-835 | Yüksek7,5 | — | %4,6 | 13 Mar 2018 |
31İzleyin | CVE-2012-2140İstismar yok | The Mail gem before 2.4.3 for Ruby allows remote attackers to execute arbitrary commands via shell metacharacters in a (1) sendmail or (2) erubygems · mail gem · CWE-20 | Yüksek7,5 | — | %4,5 | 18 Tem 2012 |
31İzleyin | CVE-2013-2616İstismar yok | lib/mini_magick.rb in the MiniMagick Gem 1.3.1 for Ruby allows remote attackers to execute arbitrary commands via shell metacharacters in a rubygems · mini magick · CWE-94 | Yüksek7,5 | — | %3,6 | 20 Mar 2013 |
31İzleyin | CVE-2013-1875İstismar yok | command_wrap.rb in the command_wrap Gem for Ruby allows remote attackers to execute arbitrary commands via shell metacharacters in a URL or rubygems · command wrap · CWE-94 | Yüksek7,5 | — | %3,6 | 20 Mar 2013 |
31İzleyin | CVE-2019-8321İstismar yok | An issue was discovered in RubyGems 2.6 and later through 3.0.2.rubygems · rubygems · CWE-88 | Yüksek7,5 | — | %3,3 | 17 Haz 2019 |
31İzleyin | CVE-2019-8325İstismar yok | An issue was discovered in RubyGems 2.6 and later through 3.0.2.rubygems · rubygems · CWE-74 | Yüksek7,5 | — | %3,3 | 17 Haz 2019 |
31İzleyin | CVE-2019-8323İstismar yok | An issue was discovered in RubyGems 2.6 and later through 3.0.2.rubygems · rubygems · CWE-74 | Yüksek7,5 | — | %3,3 | 17 Haz 2019 |
31İzleyin | CVE-2019-8322İstismar yok | An issue was discovered in RubyGems 2.6 and later through 3.0.2.rubygems · rubygems · CWE-74 | Yüksek7,5 | — | %3,3 | 17 Haz 2019 |
31İzleyin | CVE-2013-2615İstismar yok | lib/entry_controller.rb in the fastreader Gem 1.0.8 for Ruby allows remote attackers to execute arbitrary commands via shell metacharacters rubygems · fastreader · CWE-94 | Yüksek7,5 | — | %2,3 | 20 Mar 2013 |
31İzleyin | CVE-2022-29176İstismar yok | Unauthorized gem takeover for some gems on rubygems.orgrubygems · rubygems.org · CWE-862 | Yüksek7,5 | — | %1,9 | 5 May 2022 |
30İzleyin | CVE-2019-8320İstismar yok | A Directory Traversal issue was discovered in RubyGems 2.7.6 and later through 3.0.2.rubygems · rubygems · CWE-22 | Yüksek7,4 | — | %4,2 | 6 Haz 2019 |
30İzleyin | CVE-2022-29218İstismar yok | Unauthorized takeover for new versions of some platform-specific gemsrubygems · rubygems.org · CWE-269 | Yüksek7,5 | — | %1,3 | 12 May 2022 |
30İzleyin | CVE-2023-40165İstismar yok | Unauthorized gem replacement for full names ending in numbers on rubygems.orgrubygems · rubygems.org · CWE-20 | Yüksek7,5 | — | %0,5 | 17 Ağu 2023 |
- CVE-2017-090344Planlayın
RubyGems versions between 2.0.0 and 2.6.13 are vulnerable to a possible remote code execution vulnerability.
KritikCVSS 9,8İstismar yokEPSS %16rubygems · rubygems11 Eki 2017
- CVE-2017-089942Planlayın
RubyGems version 2.6.12 and earlier is vulnerable to maliciously crafted gem specifications that include terminal escape characters.
KritikCVSS 9,8İstismar yokEPSS %11rubygems · rubygems31 Ağu 2017
- CVE-2018-100007640Planlayın
RubyGems version Ruby 2.2 series: 2.2.9 and earlier, Ruby 2.3 series: 2.3.6 and earlier, Ruby 2.4 series: 2.4.3 and earlier, Ruby 2.5 series
KritikCVSS 9,8İstismar yokEPSS %3rubygems · rubygems13 Mar 2018
- CVE-2017-090139İzleyin
RubyGems version 2.6.12 and earlier fails to validate specification names, allowing a maliciously crafted gem to potentially overwrite any f
YüksekCVSS 7,5Kavram kanıtıEPSS %29rubygems · rubygems31 Ağu 2017
- CVE-2024-2165439İzleyin
rubygems.org MFA Bypass through password reset function could allow account takeover
KritikCVSS 9,8İstismar yokEPSS %0rubygems · rubygems.org12 Oca 2024
- CVE-2019-832436İzleyin
An issue was discovered in RubyGems 2.6 and later through 3.0.2.
YüksekCVSS 8,8İstismar yokEPSS %3rubygems · rubygems17 Haz 2019
- CVE-2022-3607335İzleyin
RubyGems allows creation of users with arbitrary unverified emails
YüksekCVSS 8,8İstismar yokEPSS %1rubygems · rubygems7 Eyl 2022
- CVE-2013-026934İzleyin
The JSON gem before 1.5.5, 1.6.x before 1.6.8, and 1.7.x before 1.7.7 for Ruby allows remote attackers to cause a denial of service (resourc
YüksekCVSS 7,5Kavram kanıtıEPSS %13rubygems · json gem12 Şub 2013
- CVE-2017-090233İzleyin
RubyGems version 2.6.12 and earlier is vulnerable to a DNS hijacking vulnerability that allows a MITM attacker to force the RubyGems client
YüksekCVSS 8,1İstismar yokEPSS %5rubygems · rubygems31 Ağu 2017
- CVE-2017-090032İzleyin
RubyGems version 2.6.12 and earlier is vulnerable to maliciously crafted gem specifications to cause a denial of service attack against Ruby
YüksekCVSS 7,5İstismar yokEPSS %8rubygems · rubygems31 Ağu 2017
- CVE-2018-100007432İzleyin
RubyGems version Ruby 2.2 series: 2.2.9 and earlier, Ruby 2.3 series: 2.3.6 and earlier, Ruby 2.4 series: 2.4.3 and earlier, Ruby 2.5 series
YüksekCVSS 7,8İstismar yokEPSS %3rubygems · rubygems13 Mar 2018
- CVE-2018-100007331İzleyin
RubyGems version Ruby 2.2 series: 2.2.9 and earlier, Ruby 2.3 series: 2.3.6 and earlier, Ruby 2.4 series: 2.4.3 and earlier, Ruby 2.5 series
YüksekCVSS 7,5İstismar yokEPSS %5rubygems · rubygems13 Mar 2018
- CVE-2018-100007531İzleyin
RubyGems version Ruby 2.2 series: 2.2.9 and earlier, Ruby 2.3 series: 2.3.6 and earlier, Ruby 2.4 series: 2.4.3 and earlier, Ruby 2.5 series
YüksekCVSS 7,5İstismar yokEPSS %5rubygems · rubygems13 Mar 2018
- CVE-2012-214031İzleyin
The Mail gem before 2.4.3 for Ruby allows remote attackers to execute arbitrary commands via shell metacharacters in a (1) sendmail or (2) e
YüksekCVSS 7,5İstismar yokEPSS %4rubygems · mail gem18 Tem 2012
- CVE-2013-261631İzleyin
lib/mini_magick.rb in the MiniMagick Gem 1.3.1 for Ruby allows remote attackers to execute arbitrary commands via shell metacharacters in a
YüksekCVSS 7,5İstismar yokEPSS %4rubygems · mini magick20 Mar 2013
- CVE-2013-187531İzleyin
command_wrap.rb in the command_wrap Gem for Ruby allows remote attackers to execute arbitrary commands via shell metacharacters in a URL or
YüksekCVSS 7,5İstismar yokEPSS %4rubygems · command wrap20 Mar 2013
- CVE-2019-832131İzleyin
An issue was discovered in RubyGems 2.6 and later through 3.0.2.
YüksekCVSS 7,5İstismar yokEPSS %3rubygems · rubygems17 Haz 2019
- CVE-2019-832531İzleyin
An issue was discovered in RubyGems 2.6 and later through 3.0.2.
YüksekCVSS 7,5İstismar yokEPSS %3rubygems · rubygems17 Haz 2019
- CVE-2019-832331İzleyin
An issue was discovered in RubyGems 2.6 and later through 3.0.2.
YüksekCVSS 7,5İstismar yokEPSS %3rubygems · rubygems17 Haz 2019
- CVE-2019-832231İzleyin
An issue was discovered in RubyGems 2.6 and later through 3.0.2.
YüksekCVSS 7,5İstismar yokEPSS %3rubygems · rubygems17 Haz 2019
- CVE-2013-261531İzleyin
lib/entry_controller.rb in the fastreader Gem 1.0.8 for Ruby allows remote attackers to execute arbitrary commands via shell metacharacters
YüksekCVSS 7,5İstismar yokEPSS %2rubygems · fastreader20 Mar 2013
- CVE-2022-2917631İzleyin
Unauthorized gem takeover for some gems on rubygems.org
YüksekCVSS 7,5İstismar yokEPSS %2rubygems · rubygems.org5 May 2022
- CVE-2019-832030İzleyin
A Directory Traversal issue was discovered in RubyGems 2.7.6 and later through 3.0.2.
YüksekCVSS 7,4İstismar yokEPSS %4rubygems · rubygems6 Haz 2019
- CVE-2022-2921830İzleyin
Unauthorized takeover for new versions of some platform-specific gems
YüksekCVSS 7,5İstismar yokEPSS %1rubygems · rubygems.org12 May 2022
- CVE-2023-4016530İzleyin
Unauthorized gem replacement for full names ending in numbers on rubygems.org
YüksekCVSS 7,5İstismar yokEPSS %0rubygems · rubygems.org17 Ağu 2023