Improper Neutralization of Argument Delimiters in a Command in bundler - CVE-2021-43809
Published: January 11, 2024 / Updated: April 23, 2026
bundler
Gentoo Linux
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Real Time 15
SUSE Manager Retail Branch Server
SUSE Manager Server
Anolis OS
SUSE Linux Enterprise Server 15 SP2 LTSS
SUSE Linux Enterprise Server 15 SP3 LTSS
SUSE Linux Enterprise Server 15 SP4 LTSS
SUSE Linux Enterprise Desktop 15 SP4 LTSS
Basesystem Module
openSUSE Leap
openEuler
Software Support app (Android)
Software Support App (iOS)
Cloud Pak for Network Automation
rubygem-net-telnet
rubygem-abrt-doc
rubygem-abrt
rubygem-xmlrpc
rubygem-io-console
rubygem-mysql2-doc
rubygem-mysql2
rubygem-pg
rubygem-pg-doc
rubygem-power_assert
rubygem-did_you_mean
rubygem-bigdecimal
rubygem-bundler-doc
rubygem-bundler
ruby2.5-rubygem-bundler-doc
ruby2.5-rubygem-bundler
rubygem-json
rubygem-openssl
dev-ruby/bundler
rubygem-bundler-help
rubygem-mongo
rubygem-mongo-doc
ruby-irb
ruby
ruby-devel
ruby-libs
ruby-doc
rubygems
rubygems-devel
rubygem-psych
rubygem-test-unit
rubygem-bson
rubygem-bson-doc
rubygem-minitest
rubygem-rdoc
rubygem-rake
Netcool Operations Insight
Detailed vulnerability description
The vulnerability allows a local user to execute arbitrary code on the target system.
The vulnerability occurs when working with untrusted and apparently harmless `Gemfile`'s. A local user can trick the victim into opening a specially crafted directory containing a `Gemfile` file that declares a dependency that is located in a Git repository and execute arbitrary code on the target system.
How to mitigate CVE-2021-43809
Sources
- https://github.com/rubygems/rubygems/commit/a4f2f8ac17e6ce81c689527a8b6f14381060d95f
- https://github.com/rubygems/rubygems/security/advisories/GHSA-fj7f-vq84-fh43
- https://github.com/rubygems/rubygems/pull/5142
- https://github.com/rubygems/rubygems/commit/0fad1ccfe9dd7a3c5b82c1496df3c2b4842870d3
- https://www.sonarsource.com/blog/securing-developer-tools-package-managers/