CVE-2013-0334
Bundler may install gems from a different source than expected
EPSS 0.50%
Description
Bundler before 1.7, when multiple top-level source lines are used, allows remote attackers to install arbitrary gems by creating a gem with the same name as another gem in a different source.
How to fix CVE-2013-0334
To remediate CVE-2013-0334, upgrade the affected package to a fixed version below.
- RubyGems/bundler—upgrade to 1.7.0 or later
Is CVE-2013-0334 being exploited?
Low — EPSS is 0.5%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 1.7.0