Junglewise Threat Intelligence

CVE-2016-7954: Bundler allows attacker to inject arbitrary code via secondary Gem source

CVE-2016-7954 · Severity: low · CVSS 3 · Published 2022-05-14

Technologies: bundler (RubyGems). Vendors: RubyGems.

Executive brief

Bundler allows attacker to inject arbitrary code via secondary Gem source

Affected products

  • RubyGems bundler

Related threats