Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!

Bug 798135 (CVE-2020-36327)

Summary: <dev-ruby/bundler-2.2.18: dependency confusion (CVE-2020-36327)
Product: Gentoo Security Reporter: John Helmert III <ajak>
Component: VulnerabilitiesAssignee: Gentoo Security <security>
Status: RESOLVED FIXED    
Severity: minor CC: ruby
Priority: Normal    
Version: unspecified   
Hardware: All   
OS: Linux   
URL: https://bundler.io/blog/2021/02/15/a-more-secure-bundler-we-fixed-our-source-priorities.html
Whiteboard: B3 [glsa+]
Package list:
Runtime testing required: ---
Bug Depends on: 890915    
Bug Blocks:    

Description John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2021-06-24 01:51:34 UTC
CVE-2020-36327:

Bundler 1.16.0 through 2.2.9 and 2.2.11 through 2.2.16 sometimes chooses a dependency source based on the highest gem version number, which means that a rogue gem found at a public source may be chosen, even if the intended choice was a private gem that is a dependency of another private gem that is explicitly depended on by the application. NOTE: it is not correct to use CVE-2021-24105 for every "Dependency Confusion" issue in every product.


URL indicates this is properly fixed in 2.2.18, so please stabilize.
Comment 1 NATTkA bot gentoo-dev 2021-07-29 17:21:22 UTC Comment hidden (obsolete)
Comment 2 NATTkA bot gentoo-dev 2021-07-29 17:29:30 UTC Comment hidden (obsolete)
Comment 3 NATTkA bot gentoo-dev 2021-07-29 17:37:28 UTC Comment hidden (obsolete)
Comment 4 NATTkA bot gentoo-dev 2021-07-29 17:45:33 UTC Comment hidden (obsolete)
Comment 5 NATTkA bot gentoo-dev 2021-07-29 17:53:38 UTC Comment hidden (obsolete)
Comment 6 NATTkA bot gentoo-dev 2021-07-29 18:01:31 UTC Comment hidden (obsolete)
Comment 7 NATTkA bot gentoo-dev 2021-07-29 18:09:53 UTC
Package list is empty or all packages have requested keywords.
Comment 8 John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2021-08-07 17:28:07 UTC
Ping.
Comment 9 Larry the Git Cow gentoo-dev 2024-08-10 08:24:00 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/data/glsa.git/commit/?id=cf9015f3dee372a335e1d143abb09a32c988e7fa

commit cf9015f3dee372a335e1d143abb09a32c988e7fa
Author:     GLSAMaker <glsamaker@gentoo.org>
AuthorDate: 2024-08-10 08:23:41 +0000
Commit:     Hans de Graaff <graaff@gentoo.org>
CommitDate: 2024-08-10 08:23:53 +0000

    [ GLSA 202408-22 ] Bundler: Multiple Vulnerabilities
    
    Bug: https://bugs.gentoo.org/743214
    Bug: https://bugs.gentoo.org/798135
    Bug: https://bugs.gentoo.org/828884
    Signed-off-by: GLSAMaker <glsamaker@gentoo.org>
    Signed-off-by: Hans de Graaff <graaff@gentoo.org>

 glsa-202408-22.xml | 46 ++++++++++++++++++++++++++++++++++++++++++++++
 1 file changed, 46 insertions(+)