CVE Vulnerabilities

CVE-2020-36327

Published: Apr 29, 2021 | Modified: Nov 21, 2024
CVSS 3.x
8.8
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS 2.x
9.3 HIGH
AV:N/AC:M/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
8.8 IMPORTANT
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Bundler 1.16.0 through 2.2.9 and 2.2.11 through 2.2.16 sometimes chooses a dependency source based on the highest gem version number, which means that a rogue gem found at a public source may be chosen, even if the intended choice was a private gem that is a dependency of another private gem that is explicitly depended on by the application. NOTE: it is not correct to use CVE-2021-24105 for every Dependency Confusion issue in every product.

Affected Software

NameVendorStart VersionEnd Version
BundlerBundler1.16.0 (including)2.2.10 (excluding)
BundlerBundler2.2.11 (including)2.2.16 (including)
Red Hat Enterprise Linux 8RedHatruby:2.7-8040020210728141159.522a0ee4*
Red Hat Enterprise Linux 8RedHatruby:2.6-8050020211215144356.c5368500*
Red Hat Enterprise Linux 8RedHatruby:2.5-8050020220112131355.c5368500*
Red Hat Enterprise Linux 8.1 Update Services for SAP SolutionsRedHatruby:2.5-8010020220201125517.c27ad7f8*
Red Hat Enterprise Linux 8.1 Update Services for SAP SolutionsRedHatruby:2.6-8010020220201152941.c27ad7f8*
Red Hat Enterprise Linux 8.2 Extended Update SupportRedHatruby:2.5-8020020220201125131.4cda2c84*
Red Hat Enterprise Linux 8.2 Extended Update SupportRedHatruby:2.6-8020020220201131207.4cda2c84*
Red Hat Enterprise Linux 8.4 Extended Update SupportRedHatruby:2.6-8040020220131135901.522a0ee4*
Red Hat Enterprise Linux 8.4 Extended Update SupportRedHatruby:2.5-8040020220201123518.522a0ee4*
Red Hat Software Collections for Red Hat Enterprise Linux 7RedHatrh-ruby27-ruby-0:2.7.4-130.el7*
Red Hat Software Collections for Red Hat Enterprise Linux 7RedHatrh-ruby30-ruby-0:3.0.2-148.el7*
Red Hat Software Collections for Red Hat Enterprise Linux 7RedHatrh-ruby26-ruby-0:2.6.9-120.el7*
Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUSRedHatrh-ruby27-ruby-0:2.7.4-130.el7*
Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUSRedHatrh-ruby30-ruby-0:3.0.2-148.el7*
BundlerUbuntubionic*
BundlerUbuntufocal*
BundlerUbuntugroovy*
BundlerUbuntuhirsute*
BundlerUbuntutrusty*
BundlerUbuntuxenial*

References