Summary: | <dev-ruby/bundler-2.2.18: dependency confusion (CVE-2020-36327) | ||
---|---|---|---|
Product: | Gentoo Security | Reporter: | John Helmert III <ajak> |
Component: | Vulnerabilities | Assignee: | Gentoo Security <security> |
Status: | RESOLVED FIXED | ||
Severity: | minor | CC: | ruby |
Priority: | Normal | ||
Version: | unspecified | ||
Hardware: | All | ||
OS: | Linux | ||
URL: | https://bundler.io/blog/2021/02/15/a-more-secure-bundler-we-fixed-our-source-priorities.html | ||
Whiteboard: | B3 [glsa+] | ||
Package list: | Runtime testing required: | --- | |
Bug Depends on: | 890915 | ||
Bug Blocks: |
Description
John Helmert III
2021-06-24 01:51:34 UTC
Package list is empty or all packages have requested keywords. Package list is empty or all packages have requested keywords. Package list is empty or all packages have requested keywords. Package list is empty or all packages have requested keywords. Package list is empty or all packages have requested keywords. Package list is empty or all packages have requested keywords. Package list is empty or all packages have requested keywords. Ping. The bug has been referenced in the following commit(s): https://gitweb.gentoo.org/data/glsa.git/commit/?id=cf9015f3dee372a335e1d143abb09a32c988e7fa commit cf9015f3dee372a335e1d143abb09a32c988e7fa Author: GLSAMaker <glsamaker@gentoo.org> AuthorDate: 2024-08-10 08:23:41 +0000 Commit: Hans de Graaff <graaff@gentoo.org> CommitDate: 2024-08-10 08:23:53 +0000 [ GLSA 202408-22 ] Bundler: Multiple Vulnerabilities Bug: https://bugs.gentoo.org/743214 Bug: https://bugs.gentoo.org/798135 Bug: https://bugs.gentoo.org/828884 Signed-off-by: GLSAMaker <glsamaker@gentoo.org> Signed-off-by: Hans de Graaff <graaff@gentoo.org> glsa-202408-22.xml | 46 ++++++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 46 insertions(+) |