Authentication Bypass Affecting bundler package, versions < 1.3.0.pre.8
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-RUBY-BUNDLER-20063
- published 11 Feb 2013
- disclosed 11 Feb 2013
- credit Unknown
Overview
bundler
is a dependencies manager.
Affected versions of this Gem contain a flaw as SSL certificates are not properly validated. By spoofing the SSL server via a certificate that appears valid, an attacker with the ability to intercept network traffic (e.g. MiTM, DNS cache poisoning) can disclose and optionally manipulate transmitted data.
References
CVSS Scores
version 3.1