Critical
Low
Medium

CVE-2022-29176 — RubyGems Package Takeover

Overview

Critical
Low
Medium
No items found.

Package: rubygems-update

Impact: Unauthorized gem removal and replacement

Fix: Update RubyGems to v3.3.12+

Year: 2022

CVSS:

Severity:

Affected Components

Location

* app/models/version.rb

* def self.find_from_slug!(rubygem_id, slug)

Stop the waste.
Protect your environment with Kodem.

Get a personalized demo
Get a personalized demo