VDB
Sign up
CRITICAL9.8

GHSA-mc6j-h948-v2p6

RubyGems Improper Verification of Cryptographic Signature vulnerability

Quick fix

GHSA-mc6j-h948-v2p6 — rubygems-update: upgrade to the fixed version with the command below.

bundle update rubygems-update

Details

RubyGems version Ruby 2.2 series: 2.2.9 and earlier, Ruby 2.3 series: 2.3.6 and earlier, Ruby 2.4 series: 2.4.3 and earlier, and Ruby 2.5 series: 2.5.0 and earlier, prior to trunk revision 62422 contain an Improper Verification of Cryptographic Signature vulnerability in package.rb. This can result in a mis-signed gem being installed, as the tarball would contain multiple gem signatures. This vulnerability has been fixed in 2.7.6.

Are you affected?

Enter the version of the package you're using.

Affected packages

RubyGems/rubygems-update
Introduced in: 2.2.0Fixed in: 2.7.6
Fixbundle update rubygems-update
Maven/org.jruby:jruby-stdlib
Introduced in: 0Fixed in: 9.1.16.0
Fix# pom.xml: bump <version>9.1.16.0</version> for org.jruby:jruby-stdlib

References