MEDIUMRubyGems
GHSA-49jx-9cmc-xjxm· CVE-2013-0334Bundler may install gems from a different source than expected
Modified: 12/6/2024
package
pkg:rubygems/bundler
Bundler may install gems from a different source than expected
Modified: 12/6/2024
Local Code Execution through Argument Injection via dash leading git url parameter in Gemfile.
Modified: 7/8/2026
Dependency Confusion in Bundler
Modified: 12/5/2024
Insecure path handling in Bundler
Modified: 2/16/2024
Bundler allows attacker to inject arbitrary code via secondary Gem source
Modified: 4/14/2025