Записи rubygems
35 опубликованных записей вендора rubygems.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 6
- С записью об исправлении
- 80 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-20 Improper Input Validation6
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')4
- CWE-94 Improper Control of Generation of Code ('Code Injection')4
- CWE-310 Cryptographic Issues3
- CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')3
- CWE-287 Improper Authentication2
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEОхват bug bounty
Вендор продукта присутствует в публичной программе. Сопоставление по имени; проверьте текст scope в программе.
Все записи
35 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
44В плане | CVE-2017-0903Эксплойта нет | RubyGems versions between 2.0.0 and 2.6.13 are vulnerable to a possible remote code execution vulnerability.rubygems · rubygems · CWE-502 | Критическая9,8 | — | 15,9 % | 11 окт. 2017 г. |
42В плане | CVE-2017-0899Эксплойта нет | RubyGems version 2.6.12 and earlier is vulnerable to maliciously crafted gem specifications that include terminal escape characters.rubygems · rubygems · CWE-150 | Критическая9,8 | — | 10,8 % | 31 авг. 2017 г. |
40В плане | CVE-2018-1000076Эксплойта нет | RubyGems version Ruby 2.2 series: 2.2.9 and earlier, Ruby 2.3 series: 2.3.6 and earlier, Ruby 2.4 series: 2.4.3 and earlier, Ruby 2.5 seriesrubygems · rubygems · CWE-347 | Критическая9,8 | — | 2,9 % | 13 мар. 2018 г. |
39Наблюдать | CVE-2017-0901Proof of concept | RubyGems version 2.6.12 and earlier fails to validate specification names, allowing a maliciously crafted gem to potentially overwrite any frubygems · rubygems · CWE-22 | Высокая7,5 | — | 28,7 % | 31 авг. 2017 г. |
39Наблюдать | CVE-2024-21654Эксплойта нет | rubygems.org MFA Bypass through password reset function could allow account takeoverrubygems · rubygems.org · CWE-287 | Критическая9,8 | — | 0,5 % | 12 янв. 2024 г. |
36Наблюдать | CVE-2019-8324Эксплойта нет | An issue was discovered in RubyGems 2.6 and later through 3.0.2.rubygems · rubygems · CWE-94 | Высокая8,8 | — | 3,2 % | 17 июн. 2019 г. |
35Наблюдать | CVE-2022-36073Эксплойта нет | RubyGems allows creation of users with arbitrary unverified emailsrubygems · rubygems · CWE-287 | Высокая8,8 | — | 1,0 % | 7 сент. 2022 г. |
34Наблюдать | CVE-2013-0269Proof of concept | The JSON gem before 1.5.5, 1.6.x before 1.6.8, and 1.7.x before 1.7.7 for Ruby allows remote attackers to cause a denial of service (resourcrubygems · json gem · CWE-20 | Высокая7,5 | — | 13,9 % | 12 февр. 2013 г. |
33Наблюдать | CVE-2017-0900Эксплойта нет | RubyGems version 2.6.12 and earlier is vulnerable to maliciously crafted gem specifications to cause a denial of service attack against Rubyrubygems · rubygems · CWE-20 | Высокая7,5 | — | 8,5 % | 31 авг. 2017 г. |
33Наблюдать | CVE-2017-0902Эксплойта нет | RubyGems version 2.6.12 and earlier is vulnerable to a DNS hijacking vulnerability that allows a MITM attacker to force the RubyGems client rubygems · rubygems · CWE-350 | Высокая8,1 | — | 4,7 % | 31 авг. 2017 г. |
32Наблюдать | CVE-2018-1000074Эксплойта нет | RubyGems version Ruby 2.2 series: 2.2.9 and earlier, Ruby 2.3 series: 2.3.6 and earlier, Ruby 2.4 series: 2.4.3 and earlier, Ruby 2.5 seriesrubygems · rubygems · CWE-502 | Высокая7,8 | — | 2,9 % | 13 мар. 2018 г. |
31Наблюдать | CVE-2018-1000073Эксплойта нет | RubyGems version Ruby 2.2 series: 2.2.9 and earlier, Ruby 2.3 series: 2.3.6 and earlier, Ruby 2.4 series: 2.4.3 and earlier, Ruby 2.5 seriesrubygems · rubygems · CWE-59 | Высокая7,5 | — | 4,9 % | 13 мар. 2018 г. |
31Наблюдать | CVE-2018-1000075Эксплойта нет | RubyGems version Ruby 2.2 series: 2.2.9 and earlier, Ruby 2.3 series: 2.3.6 and earlier, Ruby 2.4 series: 2.4.3 and earlier, Ruby 2.5 seriesrubygems · rubygems · CWE-835 | Высокая7,5 | — | 4,6 % | 13 мар. 2018 г. |
31Наблюдать | CVE-2012-2140Эксплойта нет | The Mail gem before 2.4.3 for Ruby allows remote attackers to execute arbitrary commands via shell metacharacters in a (1) sendmail or (2) erubygems · mail gem · CWE-20 | Высокая7,5 | — | 4,5 % | 18 июл. 2012 г. |
31Наблюдать | CVE-2013-2616Эксплойта нет | lib/mini_magick.rb in the MiniMagick Gem 1.3.1 for Ruby allows remote attackers to execute arbitrary commands via shell metacharacters in a rubygems · mini magick · CWE-94 | Высокая7,5 | — | 3,6 % | 20 мар. 2013 г. |
31Наблюдать | CVE-2013-1875Эксплойта нет | command_wrap.rb in the command_wrap Gem for Ruby allows remote attackers to execute arbitrary commands via shell metacharacters in a URL or rubygems · command wrap · CWE-94 | Высокая7,5 | — | 3,6 % | 20 мар. 2013 г. |
31Наблюдать | CVE-2019-8321Эксплойта нет | An issue was discovered in RubyGems 2.6 and later through 3.0.2.rubygems · rubygems · CWE-88 | Высокая7,5 | — | 3,4 % | 17 июн. 2019 г. |
31Наблюдать | CVE-2019-8325Эксплойта нет | An issue was discovered in RubyGems 2.6 and later through 3.0.2.rubygems · rubygems · CWE-74 | Высокая7,5 | — | 3,4 % | 17 июн. 2019 г. |
31Наблюдать | CVE-2019-8323Эксплойта нет | An issue was discovered in RubyGems 2.6 and later through 3.0.2.rubygems · rubygems · CWE-74 | Высокая7,5 | — | 3,4 % | 17 июн. 2019 г. |
31Наблюдать | CVE-2019-8322Эксплойта нет | An issue was discovered in RubyGems 2.6 and later through 3.0.2.rubygems · rubygems · CWE-74 | Высокая7,5 | — | 3,4 % | 17 июн. 2019 г. |
31Наблюдать | CVE-2013-2615Эксплойта нет | lib/entry_controller.rb in the fastreader Gem 1.0.8 for Ruby allows remote attackers to execute arbitrary commands via shell metacharacters rubygems · fastreader · CWE-94 | Высокая7,5 | — | 2,3 % | 20 мар. 2013 г. |
31Наблюдать | CVE-2022-29176Эксплойта нет | Unauthorized gem takeover for some gems on rubygems.orgrubygems · rubygems.org · CWE-862 | Высокая7,5 | — | 1,9 % | 5 мая 2022 г. |
30Наблюдать | CVE-2019-8320Эксплойта нет | A Directory Traversal issue was discovered in RubyGems 2.7.6 and later through 3.0.2.rubygems · rubygems · CWE-22 | Высокая7,4 | — | 4,2 % | 6 июн. 2019 г. |
30Наблюдать | CVE-2022-29218Эксплойта нет | Unauthorized takeover for new versions of some platform-specific gemsrubygems · rubygems.org · CWE-269 | Высокая7,5 | — | 1,3 % | 12 мая 2022 г. |
30Наблюдать | CVE-2023-40165Эксплойта нет | Unauthorized gem replacement for full names ending in numbers on rubygems.orgrubygems · rubygems.org · CWE-20 | Высокая7,5 | — | 0,5 % | 17 авг. 2023 г. |
- CVE-2017-090344В плане
RubyGems versions between 2.0.0 and 2.6.13 are vulnerable to a possible remote code execution vulnerability.
КритическаяCVSS 9,8Эксплойта нетEPSS 16 %rubygems · rubygems11 окт. 2017 г.
- CVE-2017-089942В плане
RubyGems version 2.6.12 and earlier is vulnerable to maliciously crafted gem specifications that include terminal escape characters.
КритическаяCVSS 9,8Эксплойта нетEPSS 11 %rubygems · rubygems31 авг. 2017 г.
- CVE-2018-100007640В плане
RubyGems version Ruby 2.2 series: 2.2.9 and earlier, Ruby 2.3 series: 2.3.6 and earlier, Ruby 2.4 series: 2.4.3 and earlier, Ruby 2.5 series
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %rubygems · rubygems13 мар. 2018 г.
- CVE-2017-090139Наблюдать
RubyGems version 2.6.12 and earlier fails to validate specification names, allowing a maliciously crafted gem to potentially overwrite any f
ВысокаяCVSS 7,5Proof of conceptEPSS 29 %rubygems · rubygems31 авг. 2017 г.
- CVE-2024-2165439Наблюдать
rubygems.org MFA Bypass through password reset function could allow account takeover
КритическаяCVSS 9,8Эксплойта нетEPSS 0 %rubygems · rubygems.org12 янв. 2024 г.
- CVE-2019-832436Наблюдать
An issue was discovered in RubyGems 2.6 and later through 3.0.2.
ВысокаяCVSS 8,8Эксплойта нетEPSS 3 %rubygems · rubygems17 июн. 2019 г.
- CVE-2022-3607335Наблюдать
RubyGems allows creation of users with arbitrary unverified emails
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %rubygems · rubygems7 сент. 2022 г.
- CVE-2013-026934Наблюдать
The JSON gem before 1.5.5, 1.6.x before 1.6.8, and 1.7.x before 1.7.7 for Ruby allows remote attackers to cause a denial of service (resourc
ВысокаяCVSS 7,5Proof of conceptEPSS 14 %rubygems · json gem12 февр. 2013 г.
- CVE-2017-090033Наблюдать
RubyGems version 2.6.12 and earlier is vulnerable to maliciously crafted gem specifications to cause a denial of service attack against Ruby
ВысокаяCVSS 7,5Эксплойта нетEPSS 8 %rubygems · rubygems31 авг. 2017 г.
- CVE-2017-090233Наблюдать
RubyGems version 2.6.12 and earlier is vulnerable to a DNS hijacking vulnerability that allows a MITM attacker to force the RubyGems client
ВысокаяCVSS 8,1Эксплойта нетEPSS 5 %rubygems · rubygems31 авг. 2017 г.
- CVE-2018-100007432Наблюдать
RubyGems version Ruby 2.2 series: 2.2.9 and earlier, Ruby 2.3 series: 2.3.6 and earlier, Ruby 2.4 series: 2.4.3 and earlier, Ruby 2.5 series
ВысокаяCVSS 7,8Эксплойта нетEPSS 3 %rubygems · rubygems13 мар. 2018 г.
- CVE-2018-100007331Наблюдать
RubyGems version Ruby 2.2 series: 2.2.9 and earlier, Ruby 2.3 series: 2.3.6 and earlier, Ruby 2.4 series: 2.4.3 and earlier, Ruby 2.5 series
ВысокаяCVSS 7,5Эксплойта нетEPSS 5 %rubygems · rubygems13 мар. 2018 г.
- CVE-2018-100007531Наблюдать
RubyGems version Ruby 2.2 series: 2.2.9 and earlier, Ruby 2.3 series: 2.3.6 and earlier, Ruby 2.4 series: 2.4.3 and earlier, Ruby 2.5 series
ВысокаяCVSS 7,5Эксплойта нетEPSS 5 %rubygems · rubygems13 мар. 2018 г.
- CVE-2012-214031Наблюдать
The Mail gem before 2.4.3 for Ruby allows remote attackers to execute arbitrary commands via shell metacharacters in a (1) sendmail or (2) e
ВысокаяCVSS 7,5Эксплойта нетEPSS 4 %rubygems · mail gem18 июл. 2012 г.
- CVE-2013-261631Наблюдать
lib/mini_magick.rb in the MiniMagick Gem 1.3.1 for Ruby allows remote attackers to execute arbitrary commands via shell metacharacters in a
ВысокаяCVSS 7,5Эксплойта нетEPSS 4 %rubygems · mini magick20 мар. 2013 г.
- CVE-2013-187531Наблюдать
command_wrap.rb in the command_wrap Gem for Ruby allows remote attackers to execute arbitrary commands via shell metacharacters in a URL or
ВысокаяCVSS 7,5Эксплойта нетEPSS 4 %rubygems · command wrap20 мар. 2013 г.
- CVE-2019-832131Наблюдать
An issue was discovered in RubyGems 2.6 and later through 3.0.2.
ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %rubygems · rubygems17 июн. 2019 г.
- CVE-2019-832531Наблюдать
An issue was discovered in RubyGems 2.6 and later through 3.0.2.
ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %rubygems · rubygems17 июн. 2019 г.
- CVE-2019-832331Наблюдать
An issue was discovered in RubyGems 2.6 and later through 3.0.2.
ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %rubygems · rubygems17 июн. 2019 г.
- CVE-2019-832231Наблюдать
An issue was discovered in RubyGems 2.6 and later through 3.0.2.
ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %rubygems · rubygems17 июн. 2019 г.
- CVE-2013-261531Наблюдать
lib/entry_controller.rb in the fastreader Gem 1.0.8 for Ruby allows remote attackers to execute arbitrary commands via shell metacharacters
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %rubygems · fastreader20 мар. 2013 г.
- CVE-2022-2917631Наблюдать
Unauthorized gem takeover for some gems on rubygems.org
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %rubygems · rubygems.org5 мая 2022 г.
- CVE-2019-832030Наблюдать
A Directory Traversal issue was discovered in RubyGems 2.7.6 and later through 3.0.2.
ВысокаяCVSS 7,4Эксплойта нетEPSS 4 %rubygems · rubygems6 июн. 2019 г.
- CVE-2022-2921830Наблюдать
Unauthorized takeover for new versions of some platform-specific gems
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %rubygems · rubygems.org12 мая 2022 г.
- CVE-2023-4016530Наблюдать
Unauthorized gem replacement for full names ending in numbers on rubygems.org
ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %rubygems · rubygems.org17 авг. 2023 г.