Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2016-7954


Bundler 1.x might allow remote attackers to inject arbitrary Ruby code into an application by leveraging a gem name collision on a secondary source. NOTE: this might overlap CVE-2013-0334.


Published

2016-12-22T22:59:00.123

Last Modified

2025-04-12T10:46:40.837

Status

Deferred

Source

[email protected]

Severity

CVSSv3.0: 9.8 (CRITICAL)

CVSSv2 Vector

AV:N/AC:L/Au:N/C:P/I:P/A:P

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: PARTIAL
  • Availability Impact: PARTIAL
Exploitability Score

10.0

Impact Score

6.4

Weaknesses
  • Type: Primary
    CWE-94

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application bundler bundler 1.0.0 Yes
Application bundler bundler 1.0.0 Yes
Application bundler bundler 1.0.0 Yes
Application bundler bundler 1.0.0 Yes
Application bundler bundler 1.0.0 Yes
Application bundler bundler 1.0.0 Yes
Application bundler bundler 1.0.0 Yes
Application bundler bundler 1.0.0 Yes
Application bundler bundler 1.0.0 Yes
Application bundler bundler 1.0.0 Yes
Application bundler bundler 1.0.0 Yes
Application bundler bundler 1.0.0 Yes
Application bundler bundler 1.0.0 Yes
Application bundler bundler 1.0.1 Yes
Application bundler bundler 1.0.2 Yes
Application bundler bundler 1.0.3 Yes
Application bundler bundler 1.0.4 Yes
Application bundler bundler 1.0.5 Yes
Application bundler bundler 1.0.6 Yes
Application bundler bundler 1.0.7 Yes
Application bundler bundler 1.0.8 Yes
Application bundler bundler 1.0.9 Yes
Application bundler bundler 1.0.10 Yes
Application bundler bundler 1.0.11 Yes
Application bundler bundler 1.0.12 Yes
Application bundler bundler 1.0.13 Yes
Application bundler bundler 1.0.14 Yes
Application bundler bundler 1.0.15 Yes
Application bundler bundler 1.0.16 Yes
Application bundler bundler 1.0.17 Yes
Application bundler bundler 1.0.18 Yes
Application bundler bundler 1.0.19 Yes
Application bundler bundler 1.0.20 Yes
Application bundler bundler 1.0.20 Yes
Application bundler bundler 1.0.21 Yes
Application bundler bundler 1.0.21 Yes
Application bundler bundler 1.1 Yes
Application bundler bundler 1.1 Yes
Application bundler bundler 1.1 Yes
Application bundler bundler 1.1 Yes
Application bundler bundler 1.1 Yes
Application bundler bundler 1.1 Yes
Application bundler bundler 1.1 Yes
Application bundler bundler 1.1 Yes
Application bundler bundler 1.1 Yes
Application bundler bundler 1.1 Yes
Application bundler bundler 1.1 Yes
Application bundler bundler 1.1 Yes
Application bundler bundler 1.1 Yes
Application bundler bundler 1.1 Yes
Application bundler bundler 1.1 Yes
Application bundler bundler 1.1 Yes
Application bundler bundler 1.1 Yes
Application bundler bundler 1.1 Yes
Application bundler bundler 1.1 Yes
Application bundler bundler 1.1.0 Yes
Application bundler bundler 1.1.1 Yes
Application bundler bundler 1.1.2 Yes
Application bundler bundler 1.1.3 Yes
Application bundler bundler 1.1.4 Yes
Application bundler bundler 1.1.5 Yes
Application bundler bundler 1.2.0 Yes
Application bundler bundler 1.2.0 Yes
Application bundler bundler 1.2.0 Yes
Application bundler bundler 1.2.0 Yes
Application bundler bundler 1.2.0 Yes
Application bundler bundler 1.2.1 Yes
Application bundler bundler 1.2.2 Yes
Application bundler bundler 1.2.3 Yes
Application bundler bundler 1.2.4 Yes
Application bundler bundler 1.2.5 Yes
Application bundler bundler 1.3.0 Yes
Application bundler bundler 1.3.0 Yes
Application bundler bundler 1.3.0 Yes
Application bundler bundler 1.3.0 Yes
Application bundler bundler 1.3.0 Yes
Application bundler bundler 1.3.0 Yes
Application bundler bundler 1.3.0 Yes
Application bundler bundler 1.3.0 Yes
Application bundler bundler 1.3.0 Yes
Application bundler bundler 1.3.1 Yes
Application bundler bundler 1.3.2 Yes
Application bundler bundler 1.3.3 Yes
Application bundler bundler 1.3.4 Yes
Application bundler bundler 1.3.5 Yes
Application bundler bundler 1.3.6 Yes
Application bundler bundler 1.4.0 Yes
Application bundler bundler 1.4.0 Yes
Application bundler bundler 1.5.0 Yes
Application bundler bundler 1.5.0 Yes
Application bundler bundler 1.5.0 Yes
Application bundler bundler 1.5.1 Yes
Application bundler bundler 1.5.2 Yes
Application bundler bundler 1.5.3 Yes
Application bundler bundler 1.6.0 Yes
Application bundler bundler 1.6.1 Yes
Application bundler bundler 1.6.2 Yes
Application bundler bundler 1.6.3 Yes
Application bundler bundler 1.6.4 Yes
Application bundler bundler 1.6.5 Yes
Application bundler bundler 1.6.6 Yes
Application bundler bundler 1.6.7 Yes
Application bundler bundler 1.7.0 Yes
Application bundler bundler 1.7.1 Yes
Application bundler bundler 1.7.2 Yes
Application bundler bundler 1.7.3 Yes
Application bundler bundler 1.7.4 Yes
Application bundler bundler 1.7.5 Yes
Application bundler bundler 1.7.6 Yes
Application bundler bundler 1.7.7 Yes
Application bundler bundler 1.7.8 Yes
Application bundler bundler 1.7.9 Yes
Application bundler bundler 1.7.10 Yes
Application bundler bundler 1.7.11 Yes
Application bundler bundler 1.7.12 Yes
Application bundler bundler 1.7.13 Yes
Application bundler bundler 1.7.14 Yes
Application bundler bundler 1.7.15 Yes
Application bundler bundler 1.8.0 Yes
Application bundler bundler 1.8.0 Yes
Application bundler bundler 1.8.0 Yes
Application bundler bundler 1.8.1 Yes
Application bundler bundler 1.8.2 Yes
Application bundler bundler 1.8.3 Yes
Application bundler bundler 1.8.4 Yes
Application bundler bundler 1.8.5 Yes
Application bundler bundler 1.8.6 Yes
Application bundler bundler 1.8.7 Yes
Application bundler bundler 1.8.8 Yes
Application bundler bundler 1.8.9 Yes
Application bundler bundler 1.9.0 Yes
Application bundler bundler 1.9.0 Yes
Application bundler bundler 1.9.0 Yes
Application bundler bundler 1.9.0 Yes
Application bundler bundler 1.9.1 Yes
Application bundler bundler 1.9.2 Yes
Application bundler bundler 1.9.3 Yes
Application bundler bundler 1.9.4 Yes
Application bundler bundler 1.9.5 Yes
Application bundler bundler 1.9.6 Yes
Application bundler bundler 1.9.7 Yes
Application bundler bundler 1.9.8 Yes
Application bundler bundler 1.9.9 Yes
Application bundler bundler 1.9.10 Yes
Application bundler bundler 1.10.0 Yes
Application bundler bundler 1.10.0 Yes
Application bundler bundler 1.10.0 Yes
Application bundler bundler 1.10.0 Yes
Application bundler bundler 1.10.0 Yes
Application bundler bundler 1.10.1 Yes
Application bundler bundler 1.10.2 Yes
Application bundler bundler 1.10.3 Yes
Application bundler bundler 1.10.4 Yes
Application bundler bundler 1.10.5 Yes
Application bundler bundler 1.10.6 Yes
Application bundler bundler 1.11.0 Yes
Application bundler bundler 1.11.0 Yes
Application bundler bundler 1.11.0 Yes
Application bundler bundler 1.11.1 Yes
Application bundler bundler 1.11.2 Yes
Application bundler bundler 1.12.0 Yes
Application bundler bundler 1.12.0 Yes
Application bundler bundler 1.12.0 Yes
Application bundler bundler 1.12.0 Yes
Application bundler bundler 1.12.0 Yes
Application bundler bundler 1.12.0 Yes
Application bundler bundler 1.12.0 Yes
Application bundler bundler 1.12.1 Yes
Application bundler bundler 1.12.2 Yes
Application bundler bundler 1.12.3 Yes
Application bundler bundler 1.12.4 Yes
Application bundler bundler 1.12.5 Yes
Application bundler bundler 1.12.6 Yes
Application bundler bundler 1.13.0 Yes
Application bundler bundler 1.13.0 Yes
Application bundler bundler 1.13.0 Yes
Application bundler bundler 1.13.0 Yes
Application bundler bundler 1.13.1 Yes
Application bundler bundler 1.13.2 Yes
Application bundler bundler 1.13.3 Yes
Application bundler bundler 1.13.4 Yes
Application bundler bundler 1.13.5 Yes
Application bundler bundler 1.13.6 Yes

References