Vulnerability index

Browse CVEs

16 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Rubygems.org CRITICAL 9.8
CVE-2024-21654

Rubygems.org is the Ruby community's gem hosting service. Rubygems.org users with MFA enabled would normally be protected from account takeover in th…

Fix: 2024-01-08+
Fix from $2,300 2024-01-12
Rubygems.org HIGH 7.5
CVE-2023-40165

rubygems.org is the Ruby community's primary gem (library) hosting service. Insufficient input validation allowed malicious actors to replace any upl…

Fix: 2023-08-14+
Fix from $1,950 2023-08-17
Rubygems HIGH 8.8
CVE-2022-36073

RubyGems.org is the Ruby community gem host. A bug in password & email change confirmation code allowed an attacker to change their RubyGems.org acco…

Fix: 2022-08-31+
Fix from $1,950 2022-09-07
Rubygems.org HIGH 7.5
CVE-2022-29218

RubyGems is a package registry used to supply software for the Ruby language ecosystem. An ordering mistake in the code that accepts gem uploads allo…

No fix yet
Fix from $1,950 2022-05-13
Rubygems.org HIGH 7.5
CVE-2022-29176

Rubygems is a package registry used to supply software for the Ruby language ecosystem. Due to a bug in the yank action, it was possible for any Ruby…

Mitigation only
Fix from $1,950 2022-05-05
Rubygems HIGH 7.4
CVE-2019-8320

A Directory Traversal issue was discovered in RubyGems 2.7.6 and later through 3.0.2. Before making new directories or touching files (which now incl…

Fix: after 3.0.2
Fix from $1,950 2019-06-06
Rubygems HIGH 7.8
CVE-2018-1000074

RubyGems version Ruby 2.2 series: 2.2.9 and earlier, Ruby 2.3 series: 2.3.6 and earlier, Ruby 2.4 series: 2.4.3 and earlier, Ruby 2.5 series: 2.5.0 a…

Fix: after 2.5.0
Fix from $1,950 2018-03-13
Rubygems HIGH 7.5
CVE-2018-1000073

RubyGems version Ruby 2.2 series: 2.2.9 and earlier, Ruby 2.3 series: 2.3.6 and earlier, Ruby 2.4 series: 2.4.3 and earlier, Ruby 2.5 series: 2.5.0 a…

Fix: after 2.5.0
Fix from $1,950 2018-03-13
Rubygems MEDIUM 5.5
CVE-2018-1000079

RubyGems version Ruby 2.2 series: 2.2.9 and earlier, Ruby 2.3 series: 2.3.6 and earlier, Ruby 2.4 series: 2.4.3 and earlier, Ruby 2.5 series: 2.5.0 a…

Fix: after 2.5.0
Fix from $1,600 2018-03-13
Rubygems MEDIUM 5.8
CVE-2012-2125

RubyGems before 1.8.23 can redirect HTTPS connections to HTTP, which makes it easier for remote attackers to observe or modify a gem during installat…

Fix: after 1.8.22
Fix from $1,600 2013-10-01
Fastreader HIGH 7.5
CVE-2013-2615

lib/entry_controller.rb in the fastreader Gem 1.0.8 for Ruby allows remote attackers to execute arbitrary commands via shell metacharacters in a URL.

No fix yet
Fix from $1,950 2013-03-20
Mini Magick HIGH 7.5
CVE-2013-2616

lib/mini_magick.rb in the MiniMagick Gem 1.3.1 for Ruby allows remote attackers to execute arbitrary commands via shell metacharacters in a URL.

No fix yet
Fix from $1,950 2013-03-20
Command Wrap HIGH 7.5
CVE-2013-1875

command_wrap.rb in the command_wrap Gem for Ruby allows remote attackers to execute arbitrary commands via shell metacharacters in a URL or filename.

No fix yet
Fix from $1,950 2013-03-20
Json Gem HIGH 7.5
CVE-2013-0269EPSS 14%

The JSON gem before 1.5.5, 1.6.x before 1.6.8, and 1.7.x before 1.7.7 for Ruby allows remote attackers to cause a denial of service (resource consump…

Mitigation only
Fix from $1,950 2013-02-13
Mail Gem HIGH 7.5
CVE-2012-2140

The Mail gem before 2.4.3 for Ruby allows remote attackers to execute arbitrary commands via shell metacharacters in a (1) sendmail or (2) exim deliv…

Fix: after 2.4.1
Fix from $1,950 2012-07-18
Mail Gem MEDIUM 5.0
CVE-2012-2139

Directory traversal vulnerability in lib/mail/network/delivery_methods/file_delivery.rb in the Mail gem before 2.4.4 for Ruby allows remote attackers…

Fix: after 2.4.3
Fix from $1,600 2012-07-18