漏洞信息详情
Bundler 安全漏洞
漏洞简介
Bundler是一个应用软件。通过跟踪和安装所需的确切gem和版本,为Ruby项目提供了一致的环境。
Bundler 1.16.0版本至2.2.9版本和2.2.11版本至2.2.16版本存在安全漏洞,该漏洞源于有时选择依赖来源基于最高的版本号。
漏洞公告
目前厂商暂未发布修复措施解决此安全问题,建议使用此软件的用户随时关注厂商主页或参考网址以获取解决办法:
https://bundler.io/
参考网址
来源:MISC
链接:https://mensfeld.pl/2021/02/rubygems-dependency-confusion-attack-side-of-things/
来源:FEDORA
链接:https://lists.fedoraproject.org/archives/list/[email protected]/message/MWXHK5UUHVSHF7HTHMX6JY3WXDVNIHSL/
来源:MISC
链接:https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2021-24105
来源:MISC
链接:https://www.zofrex.com/blog/2021/04/29/bundler-still-vulnerable-dependency-confusion-cve-2020-36327/
来源:MISC
链接:https://bundler.io/blog/2021/02/15/a-more-secure-bundler-we-fixed-our-source-priorities.html
来源:MISC
链接:https://github.com/rubygems/rubygems/issues/3982
来源:www.cybersecurity-help.cz
链接:https://www.cybersecurity-help.cz/vdb/SB2021092218
来源:nvd.nist.gov
链接:https://nvd.nist.gov/vuln/detail/CVE-2020-36327
来源:www.cybersecurity-help.cz
链接:https://www.cybersecurity-help.cz/vdb/SB2021080913
来源:vigilance.fr
链接:https://vigilance.fr/vulnerability/Ruby-code-execution-via-Highest-Gem-Version-Number-36011
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/164211/Red-Hat-Security-Advisory-2021-3559-01.html
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.3149
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/164647/Red-Hat-Security-Advisory-2021-3982-01.html
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.3545
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/163745/Red-Hat-Security-Advisory-2021-3020-01.html
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.2646
受影响实体
暂无
补丁
暂无
还没有评论,来说两句吧...