Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3005▼ 85 respecto a la semana anterior
Críticas / altas1403▲ 41 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
37 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.3) | 0.49% | — | Rubygems.orgAIRubyAI | 29/5/2024 | 17/6/2026 | Rubygems.org is the Ruby community's gem hosting service. A Gem publisher can cause a Remote DoS when publishing a Gem. This is due to how Ruby reads the Manifest of Gem files when using Gem::Specification.from_yaml. from_yaml makes use of SafeYAML.load which allows YAML aliases inside the YAML-based metadata of a… | |
| Modificada | Crítica (9.8) | 0.48% | — | Rubygems.org | 12/1/2024 | 17/6/2026 | Rubygems.org is the Ruby community's gem hosting service. Rubygems.org users with MFA enabled would normally be protected from account takeover in the case of email account takeover. However, a workaround on the forgotten password form allows an attacker to bypass the MFA requirement and takeover the account. This… | |
| Modificada | Alta (7.5) | 0.46% | — | Rubygems.org | 17/8/2023 | 17/6/2026 | rubygems.org is the Ruby community's primary gem (library) hosting service. Insufficient input validation allowed malicious actors to replace any uploaded gem version that had a platform, version number, or gem name matching `/-\d/`, permanently replacing the legitimate upload in the canonical gem storage bucket, and… | |
| Modificada | Alta (8.8) | 1.0% | — | Rubygems | 7/9/2022 | 17/6/2026 | RubyGems.org is the Ruby community gem host. A bug in password & email change confirmation code allowed an attacker to change their RubyGems.org account's email to an unowned email address. Having access to an account whose email has been changed could enable an attacker to save API keys for that account, and when a… | |
| Modificada | Alta (7.5) | 1.3% | — | Rubygems.org | 13/5/2022 | 17/6/2026 | RubyGems is a package registry used to supply software for the Ruby language ecosystem. An ordering mistake in the code that accepts gem uploads allowed some gems (with platforms ending in numbers, like `arm64-darwin-21`) to be temporarily replaced in the CDN cache by a malicious package. The bug has been patched, and… | |
| Modificada | Alta (7.5) | 1.9% | — | Rubygems.org | 5/5/2022 | 17/6/2026 | Rubygems is a package registry used to supply software for the Ruby language ecosystem. Due to a bug in the yank action, it was possible for any RubyGems.org user to remove and replace certain gems even if that user was not authorized to do so. To be vulnerable, a gem needed: one or more dashes in its name creation… | |
| Modificada | Alta (7.5) | 3.3% | — | RubygemsDebian LinuxOpensuse Leap | 17/6/2019 | 17/6/2026 | An issue was discovered in RubyGems 2.6 and later through 3.0.2. Gem::GemcutterUtilities#with_response may output the API response to stdout as it is. Therefore, if the API side modifies the response, escape sequence injection may occur. | |
| Modificada | Alta (7.5) | 3.3% | — | RubygemsDebian LinuxOpensuse Leap | 17/6/2019 | 17/6/2026 | An issue was discovered in RubyGems 2.6 and later through 3.0.2. The gem owner command outputs the contents of the API response directly to stdout. Therefore, if the response is crafted, escape sequence injection may occur. | |
| Modificada | Alta (7.5) | 3.3% | — | RubygemsDebian LinuxOpensuse Leap | 17/6/2019 | 17/6/2026 | An issue was discovered in RubyGems 2.6 and later through 3.0.2. Since Gem::UserInteraction#verbose calls say without escaping, escape sequence injection is possible. | |
| Modificada | Alta (7.5) | 3.3% | — | RubygemsOpensuse LeapDebian Linux | 17/6/2019 | 17/6/2026 | An issue was discovered in RubyGems 2.6 and later through 3.0.2. Since Gem::CommandManager#run calls alert_error without escaping, escape sequence injection is possible. (There are many ways to cause an error.) | |
| Modificada | Alta (8.8) | 3.2% | — | RubygemsDebian LinuxOpensuse LeapRedhat Enterprise Linux | 17/6/2019 | 17/6/2026 | An issue was discovered in RubyGems 2.6 and later through 3.0.2. A crafted gem with a multi-line name is not handled correctly. Therefore, an attacker could inject arbitrary code to the stub line of gemspec, which is eval-ed by code in ensure_loadable_spec during the preinstall check. | |
| Modificada | Alta (7.4) | 4.2% | — | Rubygems | 6/6/2019 | 17/6/2026 | A Directory Traversal issue was discovered in RubyGems 2.7.6 and later through 3.0.2. Before making new directories or touching files (which now include path-checking code for symlinks), it would delete the target destination. If that destination was hidden behind a symlink, a malicious gem could delete arbitrary… | |
| Modificada | Media (5.5) | 2.8% | — | Rubygems | 13/3/2018 | 17/6/2026 | RubyGems version Ruby 2.2 series: 2.2.9 and earlier, Ruby 2.3 series: 2.3.6 and earlier, Ruby 2.4 series: 2.4.3 and earlier, Ruby 2.5 series: 2.5.0 and earlier, prior to trunk revision 62422 contains a Directory Traversal vulnerability in gem installation that can result in the gem could write to arbitrary filesystem… | |
| Modificada | Media (6.1) | 2.7% | — | RubygemsDebian Linux | 13/3/2018 | 17/6/2026 | RubyGems version Ruby 2.2 series: 2.2.9 and earlier, Ruby 2.3 series: 2.3.6 and earlier, Ruby 2.4 series: 2.4.3 and earlier, Ruby 2.5 series: 2.5.0 and earlier, prior to trunk revision 62422 contains a Cross Site Scripting (XSS) vulnerability in gem server display of homepage attribute that can result in XSS. This… | |
| Modificada | Media (5.3) | 3.6% | — | RubygemsDebian Linux | 13/3/2018 | 17/6/2026 | RubyGems version Ruby 2.2 series: 2.2.9 and earlier, Ruby 2.3 series: 2.3.6 and earlier, Ruby 2.4 series: 2.4.3 and earlier, Ruby 2.5 series: 2.5.0 and earlier, prior to trunk revision 62422 contains a Improper Input Validation vulnerability in ruby gems specification homepage attribute that can result in a malicious… | |
| Modificada | Crítica (9.8) | 2.9% | — | RubygemsDebian Linux | 13/3/2018 | 17/6/2026 | RubyGems version Ruby 2.2 series: 2.2.9 and earlier, Ruby 2.3 series: 2.3.6 and earlier, Ruby 2.4 series: 2.4.3 and earlier, Ruby 2.5 series: 2.5.0 and earlier, prior to trunk revision 62422 contains a Improper Verification of Cryptographic Signature vulnerability in package.rb that can result in a mis-signed gem… | |
| Modificada | Alta (7.5) | 4.7% | — | RubygemsDebian Linux | 13/3/2018 | 17/6/2026 | RubyGems version Ruby 2.2 series: 2.2.9 and earlier, Ruby 2.3 series: 2.3.6 and earlier, Ruby 2.4 series: 2.4.3 and earlier, Ruby 2.5 series: 2.5.0 and earlier, prior to trunk revision 62422 contains a infinite loop caused by negative size vulnerability in ruby gem package tar header that can result in a negative size… | |
| Modificada | Alta (7.8) | 2.9% | — | Rubygems | 13/3/2018 | 17/6/2026 | RubyGems version Ruby 2.2 series: 2.2.9 and earlier, Ruby 2.3 series: 2.3.6 and earlier, Ruby 2.4 series: 2.4.3 and earlier, Ruby 2.5 series: 2.5.0 and earlier, prior to trunk revision 62422 contains a Deserialization of Untrusted Data vulnerability in owner command that can result in code execution. This attack… | |
| Modificada | Alta (7.5) | 4.9% | — | Rubygems | 13/3/2018 | 17/6/2026 | RubyGems version Ruby 2.2 series: 2.2.9 and earlier, Ruby 2.3 series: 2.3.6 and earlier, Ruby 2.4 series: 2.4.3 and earlier, Ruby 2.5 series: 2.5.0 and earlier, prior to trunk revision 62422 contains a Directory Traversal vulnerability in install_location function of package.rb that can result in path traversal when… | |
| Modificada | Crítica (9.8) | 16% | — | RubygemsDebian LinuxCanonical Ubuntu LinuxRedhat Enterprise Linux Desktop+5 | 11/10/2017 | 17/6/2026 | RubyGems versions between 2.0.0 and 2.6.13 are vulnerable to a possible remote code execution vulnerability. YAML deserialization of gem specifications can bypass class white lists. Specially crafted serialized objects can possibly be used to escalate to remote code execution. | |
| Modificada | Alta (8.1) | 4.8% | — | RubygemsDebian LinuxCanonical Ubuntu LinuxRedhat Enterprise Linux Desktop+5 | 31/8/2017 | 17/6/2026 | RubyGems version 2.6.12 and earlier is vulnerable to a DNS hijacking vulnerability that allows a MITM attacker to force the RubyGems client to download and install gems from a server that the attacker controls. | |
| Modificada | Alta (7.5) | 29% | — | RubygemsDebian LinuxCanonical Ubuntu LinuxRedhat Enterprise Linux Desktop+5 | 31/8/2017 | 17/6/2026 | RubyGems version 2.6.12 and earlier fails to validate specification names, allowing a maliciously crafted gem to potentially overwrite any file on the filesystem. | |
| Modificada | Alta (7.5) | 8.5% | — | RubygemsDebian LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+4 | 31/8/2017 | 17/6/2026 | RubyGems version 2.6.12 and earlier is vulnerable to maliciously crafted gem specifications to cause a denial of service attack against RubyGems clients who have issued a `query` command. | |
| Modificada | Crítica (9.8) | 11% | — | RubygemsDebian LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+4 | 31/8/2017 | 17/6/2026 | RubyGems version 2.6.12 and earlier is vulnerable to maliciously crafted gem specifications that include terminal escape characters. Printing the gem specification would execute terminal escape sequences. | |
| Modificada | Media (4.3) | 3.5% | — | Oracle SolarisRubygems | 25/8/2015 | 17/6/2026 | RubyGems 2.0.x before 2.0.17, 2.2.x before 2.2.5, and 2.4.x before 2.4.8 does not validate the hostname when fetching gems or making API requests, which allows remote attackers to redirect requests to arbitrary domains via a crafted DNS SRV record with a domain that is suffixed with the original domain name, aka a… |