{"schema_version":1,"title":"rubygems-update (RubyGems) vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 15 vulnerabilities in rubygems-update (RubyGems): 0 in the last 7 days and 0 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2012-2125, was published on 17 May 2022.","url":"https://junglewise.ai/threats/technologies/rubygems-update","json_url":"https://junglewise.ai/threats/technologies/rubygems-update.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/rubygems-update","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":0,"all_time":15,"critical":0,"exploited":0,"last_7_days":0,"last_30_days":0,"last_90_days":0,"last_365_days":0},"latest":[{"cve":"CVE-2012-2125","epss":0.0248,"slug":"cve-2012-2125-rubygems-https-to-http-redirect","title":"RubyGems HTTPS to HTTP redirect","severity":"info","exploited":false,"published_at":"2022-05-17T04:54:56+00:00","url":"https://junglewise.ai/threats/cve-2012-2125-rubygems-https-to-http-redirect"},{"cve":"CVE-2012-2126","epss":0.0137,"slug":"cve-2012-2126-rubygems-does-not-verify-ssl-certificate","title":"RubyGems does not verify SSL certificate","severity":"info","exploited":false,"published_at":"2022-05-17T04:54:47+00:00","url":"https://junglewise.ai/threats/cve-2012-2126-rubygems-does-not-verify-ssl-certificate"},{"cve":"CVE-2018-1000079","cvss":3,"epss":0.0278,"slug":"cve-2018-1000079-rubygems-path-traversal-vulnerability","title":"RubyGems Path Traversal vulnerability","severity":"low","exploited":false,"published_at":"2022-05-14T01:54:40+00:00","url":"https://junglewise.ai/threats/cve-2018-1000079-rubygems-path-traversal-vulnerability"},{"cve":"CVE-2017-0900","cvss":3,"epss":0.0849,"slug":"cve-2017-0900-rubygems-improper-input-validation-vulnerability","title":"RubyGems Improper Input Validation vulnerability","severity":"low","exploited":false,"published_at":"2022-05-14T01:04:09+00:00","url":"https://junglewise.ai/threats/cve-2017-0900-rubygems-improper-input-validation-vulnerability"},{"cve":"CVE-2018-1000076","cvss":3,"epss":0.0293,"slug":"cve-2018-1000076-rubygems-improper-verification-of-cryptographic-signature","title":"RubyGems Improper Verification of Cryptographic Signature vulnerability","severity":"low","exploited":false,"published_at":"2022-05-14T01:01:12+00:00","url":"https://junglewise.ai/threats/cve-2018-1000076-rubygems-improper-verification-of-cryptographic-signature"},{"cve":"CVE-2018-1000074","cvss":3,"epss":0.0288,"slug":"cve-2018-1000074-rubygems-deserialization-of-untrusted-data-vulnerability","title":"RubyGems Deserialization of Untrusted Data vulnerability","severity":"low","exploited":false,"published_at":"2022-05-14T01:01:12+00:00","url":"https://junglewise.ai/threats/cve-2018-1000074-rubygems-deserialization-of-untrusted-data-vulnerability"},{"cve":"CVE-2018-1000077","cvss":3,"epss":0.037,"slug":"cve-2018-1000077-rubygems-improper-input-validation-vulnerability","title":"RubyGems Improper Input Validation vulnerability","severity":"low","exploited":false,"published_at":"2022-05-14T01:01:09+00:00","url":"https://junglewise.ai/threats/cve-2018-1000077-rubygems-improper-input-validation-vulnerability"},{"cve":"CVE-2018-1000078","cvss":3,"epss":0.0275,"slug":"cve-2018-1000078-rubygems-cross-site-scripting-vulnerability","title":"RubyGems Cross-site Scripting vulnerability","severity":"low","exploited":false,"published_at":"2022-05-14T01:01:09+00:00","url":"https://junglewise.ai/threats/cve-2018-1000078-rubygems-cross-site-scripting-vulnerability"},{"cve":"CVE-2018-1000075","cvss":3,"epss":0.0465,"slug":"cve-2018-1000075-rubygems-infinite-loop-vulnerability","title":"RubyGems Infinite Loop vulnerability","severity":"low","exploited":false,"published_at":"2022-05-13T01:48:31+00:00","url":"https://junglewise.ai/threats/cve-2018-1000075-rubygems-infinite-loop-vulnerability"},{"cve":"CVE-2017-0903","cvss":3,"epss":0.1585,"slug":"cve-2017-0903-rubygems-vulnerable-to-deserialization-of-untrusted-data","title":"RubyGems vulnerable to Deserialization of Untrusted Data","severity":"low","exploited":false,"published_at":"2022-05-13T01:38:26+00:00","url":"https://junglewise.ai/threats/cve-2017-0903-rubygems-vulnerable-to-deserialization-of-untrusted-data"},{"cve":"CVE-2017-0901","cvss":3,"epss":0.2944,"slug":"cve-2017-0901-rubygems-may-allow-a-maliciously-crafted-gem-to-overwrite-files","title":"RubyGems may allow a maliciously crafted gem to overwrite files","severity":"low","exploited":false,"published_at":"2022-05-13T01:38:26+00:00","url":"https://junglewise.ai/threats/cve-2017-0901-rubygems-may-allow-a-maliciously-crafted-gem-to-overwrite-files"},{"cve":"CVE-2017-0902","cvss":3,"epss":0.0475,"slug":"cve-2017-0902-rubygems-has-origin-validation-error-vulnerability","title":"RubyGems has Origin Validation Error vulnerability","severity":"low","exploited":false,"published_at":"2022-05-13T01:38:25+00:00","url":"https://junglewise.ai/threats/cve-2017-0902-rubygems-has-origin-validation-error-vulnerability"},{"cve":"CVE-2017-0899","cvss":3,"epss":0.1081,"slug":"cve-2017-0899-rubygems-code-injection-vulnerability","title":"RubyGems Code Injection vulnerability","severity":"low","exploited":false,"published_at":"2022-05-13T01:38:25+00:00","url":"https://junglewise.ai/threats/cve-2017-0899-rubygems-code-injection-vulnerability"},{"cve":"CVE-2018-1000073","cvss":3,"epss":0.0491,"slug":"cve-2018-1000073-rubygems-link-following-vulnerability","title":"RubyGems Link Following vulnerability","severity":"low","exploited":false,"published_at":"2022-05-13T01:18:44+00:00","url":"https://junglewise.ai/threats/cve-2018-1000073-rubygems-link-following-vulnerability"},{"cve":"CVE-2007-0469","epss":0.0486,"slug":"cve-2007-0469-rubygems-file-overwrite-vulnerability","title":"RubyGems file overwrite vulnerability","severity":"info","exploited":false,"published_at":"2022-05-01T17:44:34+00:00","url":"https://junglewise.ai/threats/cve-2007-0469-rubygems-file-overwrite-vulnerability"}],"weekly":[{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-28","critical":0,"exploited":0,"vulnerabilities":0}],"related":[{"name":"nokogiri (RubyGems)","slug":"nokogiri","vulnerabilities":73,"url":"https://junglewise.ai/threats/technologies/nokogiri"},{"name":"rack (RubyGems)","slug":"rack","vulnerabilities":20,"url":"https://junglewise.ai/threats/technologies/rack"},{"name":"camaleon_cms (RubyGems)","slug":"camaleon-cms","vulnerabilities":19,"url":"https://junglewise.ai/threats/technologies/camaleon-cms"},{"name":"rails-html-sanitizer (RubyGems)","slug":"rails-html-sanitizer","vulnerabilities":19,"url":"https://junglewise.ai/threats/technologies/rails-html-sanitizer"},{"name":"actionpack (RubyGems)","slug":"actionpack","vulnerabilities":15,"url":"https://junglewise.ai/threats/technologies/actionpack"},{"name":"publify_core (RubyGems)","slug":"publify-core","vulnerabilities":15,"url":"https://junglewise.ai/threats/technologies/publify-core"},{"name":"loofah (RubyGems)","slug":"loofah","vulnerabilities":14,"url":"https://junglewise.ai/threats/technologies/loofah"},{"name":"fat_free_crm (RubyGems)","slug":"fat-free-crm","vulnerabilities":12,"url":"https://junglewise.ai/threats/technologies/fat-free-crm"},{"name":"passenger (RubyGems)","slug":"passenger","vulnerabilities":12,"url":"https://junglewise.ai/threats/technologies/passenger"},{"name":"oj (RubyGems)","slug":"oj","vulnerabilities":11,"url":"https://junglewise.ai/threats/technologies/oj"},{"name":"openc3 (RubyGems)","slug":"openc3","vulnerabilities":10,"url":"https://junglewise.ai/threats/technologies/openc3"},{"name":"jquery-rails (RubyGems)","slug":"jquery-rails","vulnerabilities":9,"url":"https://junglewise.ai/threats/technologies/jquery-rails"}],"technology":{"hub":true,"name":"rubygems-update (RubyGems)","slug":"rubygems-update","vendor":{"name":"RubyGems","slug":"rubygems","url":"https://junglewise.ai/threats/vendors/rubygems"},"aliases":[],"url":"https://junglewise.ai/threats/technologies/rubygems-update"},"most_severe":[{"cve":"CVE-2017-0901","cvss":3,"epss":0.2944,"slug":"cve-2017-0901-rubygems-may-allow-a-maliciously-crafted-gem-to-overwrite-files","title":"RubyGems may allow a maliciously crafted gem to overwrite files","severity":"low","exploited":false,"published_at":"2022-05-13T01:38:26+00:00","url":"https://junglewise.ai/threats/cve-2017-0901-rubygems-may-allow-a-maliciously-crafted-gem-to-overwrite-files"},{"cve":"CVE-2017-0903","cvss":3,"epss":0.1585,"slug":"cve-2017-0903-rubygems-vulnerable-to-deserialization-of-untrusted-data","title":"RubyGems vulnerable to Deserialization of Untrusted Data","severity":"low","exploited":false,"published_at":"2022-05-13T01:38:26+00:00","url":"https://junglewise.ai/threats/cve-2017-0903-rubygems-vulnerable-to-deserialization-of-untrusted-data"},{"cve":"CVE-2017-0899","cvss":3,"epss":0.1081,"slug":"cve-2017-0899-rubygems-code-injection-vulnerability","title":"RubyGems Code Injection vulnerability","severity":"low","exploited":false,"published_at":"2022-05-13T01:38:25+00:00","url":"https://junglewise.ai/threats/cve-2017-0899-rubygems-code-injection-vulnerability"},{"cve":"CVE-2017-0900","cvss":3,"epss":0.0849,"slug":"cve-2017-0900-rubygems-improper-input-validation-vulnerability","title":"RubyGems Improper Input Validation vulnerability","severity":"low","exploited":false,"published_at":"2022-05-14T01:04:09+00:00","url":"https://junglewise.ai/threats/cve-2017-0900-rubygems-improper-input-validation-vulnerability"},{"cve":"CVE-2018-1000073","cvss":3,"epss":0.0491,"slug":"cve-2018-1000073-rubygems-link-following-vulnerability","title":"RubyGems Link Following vulnerability","severity":"low","exploited":false,"published_at":"2022-05-13T01:18:44+00:00","url":"https://junglewise.ai/threats/cve-2018-1000073-rubygems-link-following-vulnerability"},{"cve":"CVE-2017-0902","cvss":3,"epss":0.0475,"slug":"cve-2017-0902-rubygems-has-origin-validation-error-vulnerability","title":"RubyGems has Origin Validation Error vulnerability","severity":"low","exploited":false,"published_at":"2022-05-13T01:38:25+00:00","url":"https://junglewise.ai/threats/cve-2017-0902-rubygems-has-origin-validation-error-vulnerability"},{"cve":"CVE-2018-1000075","cvss":3,"epss":0.0465,"slug":"cve-2018-1000075-rubygems-infinite-loop-vulnerability","title":"RubyGems Infinite Loop vulnerability","severity":"low","exploited":false,"published_at":"2022-05-13T01:48:31+00:00","url":"https://junglewise.ai/threats/cve-2018-1000075-rubygems-infinite-loop-vulnerability"},{"cve":"CVE-2018-1000077","cvss":3,"epss":0.037,"slug":"cve-2018-1000077-rubygems-improper-input-validation-vulnerability","title":"RubyGems Improper Input Validation vulnerability","severity":"low","exploited":false,"published_at":"2022-05-14T01:01:09+00:00","url":"https://junglewise.ai/threats/cve-2018-1000077-rubygems-improper-input-validation-vulnerability"},{"cve":"CVE-2018-1000076","cvss":3,"epss":0.0293,"slug":"cve-2018-1000076-rubygems-improper-verification-of-cryptographic-signature","title":"RubyGems Improper Verification of Cryptographic Signature vulnerability","severity":"low","exploited":false,"published_at":"2022-05-14T01:01:12+00:00","url":"https://junglewise.ai/threats/cve-2018-1000076-rubygems-improper-verification-of-cryptographic-signature"},{"cve":"CVE-2018-1000074","cvss":3,"epss":0.0288,"slug":"cve-2018-1000074-rubygems-deserialization-of-untrusted-data-vulnerability","title":"RubyGems Deserialization of Untrusted Data vulnerability","severity":"low","exploited":false,"published_at":"2022-05-14T01:01:12+00:00","url":"https://junglewise.ai/threats/cve-2018-1000074-rubygems-deserialization-of-untrusted-data-vulnerability"}],"generated_at":"2026-09-28T03:07:00.154823+00:00"}