rubygems records
35 published records for vendor rubygems.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 6
- With a fix record
- 80%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-20 Improper Input Validation6
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')4
- CWE-94 Improper Control of Generation of Code ('Code Injection')4
- CWE-310 Cryptographic Issues3
- CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')3
- CWE-287 Improper Authentication2
The weakness classes this vendor ships most often: where to look.
CWEBug bounty scope
The product’s vendor appears in a public program. Matched by name; verify the scope text in the program.
All records
35 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
44Plan | CVE-2017-0903No exploit | RubyGems versions between 2.0.0 and 2.6.13 are vulnerable to a possible remote code execution vulnerability.rubygems · rubygems · CWE-502 | Critical9.8 | — | 15.9% | Oct 11, 2017 |
42Plan | CVE-2017-0899No exploit | RubyGems version 2.6.12 and earlier is vulnerable to maliciously crafted gem specifications that include terminal escape characters.rubygems · rubygems · CWE-150 | Critical9.8 | — | 10.8% | Aug 31, 2017 |
40Plan | CVE-2018-1000076No exploit | RubyGems version Ruby 2.2 series: 2.2.9 and earlier, Ruby 2.3 series: 2.3.6 and earlier, Ruby 2.4 series: 2.4.3 and earlier, Ruby 2.5 seriesrubygems · rubygems · CWE-347 | Critical9.8 | — | 2.9% | Mar 13, 2018 |
39Monitor | CVE-2017-0901Proof of concept | RubyGems version 2.6.12 and earlier fails to validate specification names, allowing a maliciously crafted gem to potentially overwrite any frubygems · rubygems · CWE-22 | High7.5 | — | 28.7% | Aug 31, 2017 |
39Monitor | CVE-2024-21654No exploit | rubygems.org MFA Bypass through password reset function could allow account takeoverrubygems · rubygems.org · CWE-287 | Critical9.8 | — | 0.5% | Jan 12, 2024 |
36Monitor | CVE-2019-8324No exploit | An issue was discovered in RubyGems 2.6 and later through 3.0.2.rubygems · rubygems · CWE-94 | High8.8 | — | 3.2% | Jun 17, 2019 |
35Monitor | CVE-2022-36073No exploit | RubyGems allows creation of users with arbitrary unverified emailsrubygems · rubygems · CWE-287 | High8.8 | — | 1.0% | Sep 7, 2022 |
34Monitor | CVE-2013-0269Proof of concept | The JSON gem before 1.5.5, 1.6.x before 1.6.8, and 1.7.x before 1.7.7 for Ruby allows remote attackers to cause a denial of service (resourcrubygems · json gem · CWE-20 | High7.5 | — | 13.4% | Feb 12, 2013 |
33Monitor | CVE-2017-0902No exploit | RubyGems version 2.6.12 and earlier is vulnerable to a DNS hijacking vulnerability that allows a MITM attacker to force the RubyGems client rubygems · rubygems · CWE-350 | High8.1 | — | 4.7% | Aug 31, 2017 |
32Monitor | CVE-2017-0900No exploit | RubyGems version 2.6.12 and earlier is vulnerable to maliciously crafted gem specifications to cause a denial of service attack against Rubyrubygems · rubygems · CWE-20 | High7.5 | — | 8.3% | Aug 31, 2017 |
32Monitor | CVE-2018-1000074No exploit | RubyGems version Ruby 2.2 series: 2.2.9 and earlier, Ruby 2.3 series: 2.3.6 and earlier, Ruby 2.4 series: 2.4.3 and earlier, Ruby 2.5 seriesrubygems · rubygems · CWE-502 | High7.8 | — | 2.9% | Mar 13, 2018 |
31Monitor | CVE-2018-1000073No exploit | RubyGems version Ruby 2.2 series: 2.2.9 and earlier, Ruby 2.3 series: 2.3.6 and earlier, Ruby 2.4 series: 2.4.3 and earlier, Ruby 2.5 seriesrubygems · rubygems · CWE-59 | High7.5 | — | 4.9% | Mar 13, 2018 |
31Monitor | CVE-2018-1000075No exploit | RubyGems version Ruby 2.2 series: 2.2.9 and earlier, Ruby 2.3 series: 2.3.6 and earlier, Ruby 2.4 series: 2.4.3 and earlier, Ruby 2.5 seriesrubygems · rubygems · CWE-835 | High7.5 | — | 4.6% | Mar 13, 2018 |
31Monitor | CVE-2012-2140No exploit | The Mail gem before 2.4.3 for Ruby allows remote attackers to execute arbitrary commands via shell metacharacters in a (1) sendmail or (2) erubygems · mail gem · CWE-20 | High7.5 | — | 4.5% | Jul 18, 2012 |
31Monitor | CVE-2013-2616No exploit | lib/mini_magick.rb in the MiniMagick Gem 1.3.1 for Ruby allows remote attackers to execute arbitrary commands via shell metacharacters in a rubygems · mini magick · CWE-94 | High7.5 | — | 3.6% | Mar 20, 2013 |
31Monitor | CVE-2013-1875No exploit | command_wrap.rb in the command_wrap Gem for Ruby allows remote attackers to execute arbitrary commands via shell metacharacters in a URL or rubygems · command wrap · CWE-94 | High7.5 | — | 3.6% | Mar 20, 2013 |
31Monitor | CVE-2019-8321No exploit | An issue was discovered in RubyGems 2.6 and later through 3.0.2.rubygems · rubygems · CWE-88 | High7.5 | — | 3.3% | Jun 17, 2019 |
31Monitor | CVE-2019-8325No exploit | An issue was discovered in RubyGems 2.6 and later through 3.0.2.rubygems · rubygems · CWE-74 | High7.5 | — | 3.3% | Jun 17, 2019 |
31Monitor | CVE-2019-8323No exploit | An issue was discovered in RubyGems 2.6 and later through 3.0.2.rubygems · rubygems · CWE-74 | High7.5 | — | 3.3% | Jun 17, 2019 |
31Monitor | CVE-2019-8322No exploit | An issue was discovered in RubyGems 2.6 and later through 3.0.2.rubygems · rubygems · CWE-74 | High7.5 | — | 3.3% | Jun 17, 2019 |
31Monitor | CVE-2013-2615No exploit | lib/entry_controller.rb in the fastreader Gem 1.0.8 for Ruby allows remote attackers to execute arbitrary commands via shell metacharacters rubygems · fastreader · CWE-94 | High7.5 | — | 2.3% | Mar 20, 2013 |
31Monitor | CVE-2022-29176No exploit | Unauthorized gem takeover for some gems on rubygems.orgrubygems · rubygems.org · CWE-862 | High7.5 | — | 1.9% | May 5, 2022 |
30Monitor | CVE-2019-8320No exploit | A Directory Traversal issue was discovered in RubyGems 2.7.6 and later through 3.0.2.rubygems · rubygems · CWE-22 | High7.4 | — | 4.2% | Jun 6, 2019 |
30Monitor | CVE-2022-29218No exploit | Unauthorized takeover for new versions of some platform-specific gemsrubygems · rubygems.org · CWE-269 | High7.5 | — | 1.3% | May 12, 2022 |
30Monitor | CVE-2023-40165No exploit | Unauthorized gem replacement for full names ending in numbers on rubygems.orgrubygems · rubygems.org · CWE-20 | High7.5 | — | 0.5% | Aug 17, 2023 |
- CVE-2017-090344Plan
RubyGems versions between 2.0.0 and 2.6.13 are vulnerable to a possible remote code execution vulnerability.
CriticalCVSS 9.8No exploitEPSS 16%rubygems · rubygemsOct 11, 2017
- CVE-2017-089942Plan
RubyGems version 2.6.12 and earlier is vulnerable to maliciously crafted gem specifications that include terminal escape characters.
CriticalCVSS 9.8No exploitEPSS 11%rubygems · rubygemsAug 31, 2017
- CVE-2018-100007640Plan
RubyGems version Ruby 2.2 series: 2.2.9 and earlier, Ruby 2.3 series: 2.3.6 and earlier, Ruby 2.4 series: 2.4.3 and earlier, Ruby 2.5 series
CriticalCVSS 9.8No exploitEPSS 3%rubygems · rubygemsMar 13, 2018
- CVE-2017-090139Monitor
RubyGems version 2.6.12 and earlier fails to validate specification names, allowing a maliciously crafted gem to potentially overwrite any f
HighCVSS 7.5Proof of conceptEPSS 29%rubygems · rubygemsAug 31, 2017
- CVE-2024-2165439Monitor
rubygems.org MFA Bypass through password reset function could allow account takeover
CriticalCVSS 9.8No exploitEPSS 0%rubygems · rubygems.orgJan 12, 2024
- CVE-2019-832436Monitor
An issue was discovered in RubyGems 2.6 and later through 3.0.2.
HighCVSS 8.8No exploitEPSS 3%rubygems · rubygemsJun 17, 2019
- CVE-2022-3607335Monitor
RubyGems allows creation of users with arbitrary unverified emails
HighCVSS 8.8No exploitEPSS 1%rubygems · rubygemsSep 7, 2022
- CVE-2013-026934Monitor
The JSON gem before 1.5.5, 1.6.x before 1.6.8, and 1.7.x before 1.7.7 for Ruby allows remote attackers to cause a denial of service (resourc
HighCVSS 7.5Proof of conceptEPSS 13%rubygems · json gemFeb 12, 2013
- CVE-2017-090233Monitor
RubyGems version 2.6.12 and earlier is vulnerable to a DNS hijacking vulnerability that allows a MITM attacker to force the RubyGems client
HighCVSS 8.1No exploitEPSS 5%rubygems · rubygemsAug 31, 2017
- CVE-2017-090032Monitor
RubyGems version 2.6.12 and earlier is vulnerable to maliciously crafted gem specifications to cause a denial of service attack against Ruby
HighCVSS 7.5No exploitEPSS 8%rubygems · rubygemsAug 31, 2017
- CVE-2018-100007432Monitor
RubyGems version Ruby 2.2 series: 2.2.9 and earlier, Ruby 2.3 series: 2.3.6 and earlier, Ruby 2.4 series: 2.4.3 and earlier, Ruby 2.5 series
HighCVSS 7.8No exploitEPSS 3%rubygems · rubygemsMar 13, 2018
- CVE-2018-100007331Monitor
RubyGems version Ruby 2.2 series: 2.2.9 and earlier, Ruby 2.3 series: 2.3.6 and earlier, Ruby 2.4 series: 2.4.3 and earlier, Ruby 2.5 series
HighCVSS 7.5No exploitEPSS 5%rubygems · rubygemsMar 13, 2018
- CVE-2018-100007531Monitor
RubyGems version Ruby 2.2 series: 2.2.9 and earlier, Ruby 2.3 series: 2.3.6 and earlier, Ruby 2.4 series: 2.4.3 and earlier, Ruby 2.5 series
HighCVSS 7.5No exploitEPSS 5%rubygems · rubygemsMar 13, 2018
- CVE-2012-214031Monitor
The Mail gem before 2.4.3 for Ruby allows remote attackers to execute arbitrary commands via shell metacharacters in a (1) sendmail or (2) e
HighCVSS 7.5No exploitEPSS 4%rubygems · mail gemJul 18, 2012
- CVE-2013-261631Monitor
lib/mini_magick.rb in the MiniMagick Gem 1.3.1 for Ruby allows remote attackers to execute arbitrary commands via shell metacharacters in a
HighCVSS 7.5No exploitEPSS 4%rubygems · mini magickMar 20, 2013
- CVE-2013-187531Monitor
command_wrap.rb in the command_wrap Gem for Ruby allows remote attackers to execute arbitrary commands via shell metacharacters in a URL or
HighCVSS 7.5No exploitEPSS 4%rubygems · command wrapMar 20, 2013
- CVE-2019-832131Monitor
An issue was discovered in RubyGems 2.6 and later through 3.0.2.
HighCVSS 7.5No exploitEPSS 3%rubygems · rubygemsJun 17, 2019
- CVE-2019-832531Monitor
An issue was discovered in RubyGems 2.6 and later through 3.0.2.
HighCVSS 7.5No exploitEPSS 3%rubygems · rubygemsJun 17, 2019
- CVE-2019-832331Monitor
An issue was discovered in RubyGems 2.6 and later through 3.0.2.
HighCVSS 7.5No exploitEPSS 3%rubygems · rubygemsJun 17, 2019
- CVE-2019-832231Monitor
An issue was discovered in RubyGems 2.6 and later through 3.0.2.
HighCVSS 7.5No exploitEPSS 3%rubygems · rubygemsJun 17, 2019
- CVE-2013-261531Monitor
lib/entry_controller.rb in the fastreader Gem 1.0.8 for Ruby allows remote attackers to execute arbitrary commands via shell metacharacters
HighCVSS 7.5No exploitEPSS 2%rubygems · fastreaderMar 20, 2013
- CVE-2022-2917631Monitor
Unauthorized gem takeover for some gems on rubygems.org
HighCVSS 7.5No exploitEPSS 2%rubygems · rubygems.orgMay 5, 2022
- CVE-2019-832030Monitor
A Directory Traversal issue was discovered in RubyGems 2.7.6 and later through 3.0.2.
HighCVSS 7.4No exploitEPSS 4%rubygems · rubygemsJun 6, 2019
- CVE-2022-2921830Monitor
Unauthorized takeover for new versions of some platform-specific gems
HighCVSS 7.5No exploitEPSS 1%rubygems · rubygems.orgMay 12, 2022
- CVE-2023-4016530Monitor
Unauthorized gem replacement for full names ending in numbers on rubygems.org
HighCVSS 7.5No exploitEPSS 0%rubygems · rubygems.orgAug 17, 2023