CVE-2013-0334

medium
Published 2014-08-13 · Modified 2024-12-06
CVSS v3
CVSS v2
5.0
VIR risk
5.0

Description

Bundler may install gems from a different source than expected

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — http://bundler.io/blog/2014/08/14/bundler-may-install-gems-from-a-different-source-than-expected-cve-2013-0334.html

OS impact

OSVersionStatusFixed in
suse suse13.1affected
suse suse13.2affected
fedora fedora19affected
fedora fedora20affected
fedora fedora21affected

Package impact

EcosystemPackageVulnerableFixed
ruby RubyGemsbundler<>= 1.7.0>= 1.7.0
ruby RubyGemsbundler<1.7.01.7.0

Application impact

VendorProductVersionsFixed
bundlerbundler{"endExcluding":"1.7.0"}1.7.0

References

CWEs

CWE-20

Verify integrity in audit chain (admin only). AS-IS.