Known vulnerabilities in RubyGems

Vendor: Ruby
Software: RubyGems
Software CPE: cpe:2.3:a:ruby:rubygems:*:*:*:*:*:*:*:*
Total vulnerabilities: 19
Public exploits: 1
Known exploited (KEV): 0
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting RubyGems RubyGems is affected by 19 known vulnerabilities: 1 high, 4 medium, 14 low Critical High Medium Low

Vulnerabilities (19)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU96998 - Improper input validation
CVE-2024-35221
CWE-20 Medium
No
No
3.5.9 10.09.2024 SB2024091055
SB2024091063
SB2024091070
and 4 more
#VU54082 - Improper input validation
CWE-20 Medium
No
No
3.2.20 14.06.2021 SB2021061402
#VU20194 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2019-8321
CWE-79 Low
No
No
2.7.9, 3.0.2 13.08.2019 SB2019081320
SB2019061706
SB2019072108
and 9 more
#VU20193 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2019-8320
CWE-22 Low
No
No
2.7.9, 3.0.2 13.08.2019 SB2019081320
SB2019061706
SB2019072108
and 8 more
#VU20192 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2019-8323
CWE-79 Low
No
No
2.7.9, 3.0.2 13.08.2019 SB2019081320
SB2019061706
SB2019072108
and 10 more
#VU20191 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2019-8322
CWE-79 Low
No
No
2.7.9, 3.0.2 13.08.2019 SB2019081320
SB2019061706
SB2019072108
and 10 more
#VU20190 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2019-8325
CWE-79 Low
No
No
2.7.9, 3.0.2 13.08.2019 SB2019081320
SB2019061706
SB2019072108
and 10 more
#VU20189 - Improper Control of Generation of Code ('Code Injection')
CVE-2019-8324
CWE-94 Medium
No
No
2.7.9, 3.0.2 13.08.2019 SB2019081320
SB2019061706
SB2019072108
and 11 more
#VU11628 - Improper input validation
CVE-2018-1000077
CWE-20 Low
No
No
- 09.04.2018 SB2018021520
SB2018040507
SB2018061002
and 13 more
#VU11615 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2018-1000079
CWE-22 Low
No
No
- 08.04.2018 SB2018021520
SB2018040507
SB2018061002
and 13 more
#VU8815 - Deserialization of Untrusted Data
CVE-2017-0903
CWE-502 High
No
No
- 13.10.2017 SB2017101301
SB2017111201
SB2017121902
and 10 more
#VU8449 - Improper input validation
CVE-2017-14033
CWE-20 Low
No
No
- 15.09.2017 SB2017091505
SB2017100602
SB2017091810
and 15 more
#VU8448 - Exposure of sensitive information to an unauthorized actor
CVE-2017-10784
CWE-200 Low
No
No
- 15.09.2017 SB2017091505
SB2017100602
SB2017091810
and 17 more
#VU8447 - Improper input validation
CVE-2017-0898
CWE-20 Low
No
No
- 15.09.2017 SB2017091505
SB2017100602
SB2017091810
and 16 more
#VU8123 - Exposure of sensitive information to an unauthorized actor
CVE-2017-14064
CWE-200 Low
No
No
- 06.09.2017 SB2017090606
SB2017091505
SB2017100602
and 16 more
#VU8058 - Improper Access Control
CVE-2017-0902
CWE-284 Low
No
No
- 31.08.2017 SB2017083105
SB2017090606
SB2017090607
and 17 more
#VU8057 - Improper input validation
CVE-2017-0901
CWE-20 Medium
Available
No
- 31.08.2017 SB2017083105
SB2017090606
SB2017090607
and 18 more
#VU8056 - Improper Access Control
CVE-2017-0899
CWE-284 Low
No
No
- 31.08.2017 SB2017083105
SB2017090606
SB2017090607
and 16 more
#VU8055 - Improper input validation
CVE-2017-0900
CWE-20 Low
No
No
- 31.08.2017 SB2017083105
SB2017090606
SB2017090607
and 16 more