VDB
Sign up
HIGH8.8

GHSA-qwv2-2x8g-g43g

Gem in a Box vulnerable to Cross-site Request Forgery

Quick fix

GHSA-qwv2-2x8g-g43g — geminabox: upgrade to the fixed version with the command below.

bundle update geminabox

Details

geminabox (aka Gem in a Box) before 0.13.7 has CSRF, as demonstrated by an unintended gem upload.

Are you affected?

Enter the version of the package you're using.

Affected packages

RubyGems/geminabox
Introduced in: 0Fixed in: 0.13.7
Fixbundle update geminabox

References