Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 798135 (CVE-2020-36327) - <dev-ruby/bundler-2.2.18: dependency confusion (CVE-2020-36327)
Summary: <dev-ruby/bundler-2.2.18: dependency confusion (CVE-2020-36327)
Status: RESOLVED FIXED
Alias: CVE-2020-36327
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal minor
Assignee: Gentoo Security
URL: https://bundler.io/blog/2021/02/15/a-...
Whiteboard: B3 [glsa+]
Keywords:
Depends on: ruby30-stable
Blocks:
  Show dependency tree
 
Reported: 2021-06-24 01:51 UTC by John Helmert III
Modified: 2024-08-10 08:24 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2021-06-24 01:51:34 UTC
CVE-2020-36327:

Bundler 1.16.0 through 2.2.9 and 2.2.11 through 2.2.16 sometimes chooses a dependency source based on the highest gem version number, which means that a rogue gem found at a public source may be chosen, even if the intended choice was a private gem that is a dependency of another private gem that is explicitly depended on by the application. NOTE: it is not correct to use CVE-2021-24105 for every "Dependency Confusion" issue in every product.


URL indicates this is properly fixed in 2.2.18, so please stabilize.
Comment 1 NATTkA bot gentoo-dev 2021-07-29 17:21:22 UTC Comment hidden (obsolete)
Comment 2 NATTkA bot gentoo-dev 2021-07-29 17:29:30 UTC Comment hidden (obsolete)
Comment 3 NATTkA bot gentoo-dev 2021-07-29 17:37:28 UTC Comment hidden (obsolete)
Comment 4 NATTkA bot gentoo-dev 2021-07-29 17:45:33 UTC Comment hidden (obsolete)
Comment 5 NATTkA bot gentoo-dev 2021-07-29 17:53:38 UTC Comment hidden (obsolete)
Comment 6 NATTkA bot gentoo-dev 2021-07-29 18:01:31 UTC Comment hidden (obsolete)
Comment 7 NATTkA bot gentoo-dev 2021-07-29 18:09:53 UTC
Package list is empty or all packages have requested keywords.
Comment 8 John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2021-08-07 17:28:07 UTC
Ping.
Comment 9 Larry the Git Cow gentoo-dev 2024-08-10 08:24:00 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/data/glsa.git/commit/?id=cf9015f3dee372a335e1d143abb09a32c988e7fa

commit cf9015f3dee372a335e1d143abb09a32c988e7fa
Author:     GLSAMaker <glsamaker@gentoo.org>
AuthorDate: 2024-08-10 08:23:41 +0000
Commit:     Hans de Graaff <graaff@gentoo.org>
CommitDate: 2024-08-10 08:23:53 +0000

    [ GLSA 202408-22 ] Bundler: Multiple Vulnerabilities
    
    Bug: https://bugs.gentoo.org/743214
    Bug: https://bugs.gentoo.org/798135
    Bug: https://bugs.gentoo.org/828884
    Signed-off-by: GLSAMaker <glsamaker@gentoo.org>
    Signed-off-by: Hans de Graaff <graaff@gentoo.org>

 glsa-202408-22.xml | 46 ++++++++++++++++++++++++++++++++++++++++++++++
 1 file changed, 46 insertions(+)