Executive brief
Bundler allows attacker to inject arbitrary code via secondary Gem source
Affected products
- RubyGems bundler
Junglewise Threat Intelligence
CVE-2016-7954 · Severity: low · CVSS 3 · Published 2022-05-14
Technologies: bundler (RubyGems). Vendors: RubyGems.
Bundler allows attacker to inject arbitrary code via secondary Gem source