Description
Bundler 1.16.0 through 2.2.9 and 2.2.11 through 2.2.16 sometimes chooses a dependency source based on the highest gem version number, which means that a rogue gem found at a public source may be chosen, even if the intended choice was a private gem that is a dependency of another private gem that is explicitly depended on by the application. NOTE: it is not correct to use CVE-2021-24105 for every "Dependency Confusion" issue in every product.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-fp4w-jxhp-m23p | Dependency Confusion in Bundler |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-04T17:23:10.451Z
Reserved: 2021-04-29T00:00:00.000Z
Link: CVE-2020-36327
No data.
Status : Modified
Published: 2021-04-29T03:15:08.710
Modified: 2024-11-21T05:29:17.540
Link: CVE-2020-36327
OpenCVE Enrichment
No data.
Weaknesses
Github GHSA