CVE-2022-29176
Last modified
CVE-2022-29176 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. Rubygems is a package registry used to supply software for the Ruby language ecosystem. Due to a bug in the yank action, it was possible for any RubyGems.org user to remove and replace certain gems even if that user was not authorized to do so. EPSS estimates a 1.73% chance of exploitation in the next 30 days.
Description
Rubygems is a package registry used to supply software for the Ruby language ecosystem. Due to a bug in the yank action, it was possible for any RubyGems.org user to remove and replace certain gems even if that user was not authorized to do so. To be vulnerable, a gem needed: one or more dashes in its name creation within 30 days OR no updates for over 100 days At present, we believe this vulnerability has not been exploited. RubyGems.org sends an email to all gem owners when a gem version is published or yanked. We have not received any support emails from gem owners indicating that their gem has been yanked without authorization. An audit of gem changes for the last 18 months did not find any examples of this vulnerability being used in a malicious way. A deeper audit for any possible use of this exploit is ongoing, and we will update this advisory once it is complete. Using Bundler in --frozen or --deployment mode in CI and during deploys, as the Bundler team has always recommended, will guarantee that your application does not silently switch to versions created using this exploit. To audit your application history for possible past exploits, review your Gemfile.lock and look for gems whose platform changed when the version number did not change. For example, gemname-3.1.2 updating to gemname-3.1.2-java could indicate a possible abuse of this vulnerability. RubyGems.org has been patched and is no longer vulnerable to this issue as of the 5th of May 2022.
Metrics
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Rubygems | Rubygems.Org | All versions |
References
- https://github.com/rubygems/rubygems.org/security/advisories/GHSA-hccv-rwq6-vh79Mitigation, Third Party Advisory
- https://hackerone.com/bugs?subject=rubygems&report_id=1559856Permissions Required, Third Party Advisory
- https://security.netapp.com/advisory/ntap-20220616-0002/Third Party Advisory
- https://github.com/rubygems/rubygems.org/security/advisories/GHSA-hccv-rwq6-vh79Mitigation, Third Party Advisory
- https://hackerone.com/bugs?subject=rubygems&report_id=1559856Permissions Required, Third Party Advisory
- https://security.netapp.com/advisory/ntap-20220616-0002/Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-29176?
How severe is CVE-2022-29176?
How do I fix CVE-2022-29176?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2022
- CVE-2022-29170Grafana is an open-source platform for monitoring and observ…8.5
- CVE-2022-29171Sourcegraph is a fast and featureful code search and navigat…7.2
- CVE-2022-29172Auth0 is an authentication broker that supports both social …6.1
- CVE-2022-29173go-tuf is a Go implementation of The Update Framework (TUF).…8.8
- CVE-2022-29174countly-server is the server-side part of Countly, a product…8.1
- CVE-2022-29175Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2022-29177Go Ethereum is the official Golang implementation of the Eth…5.9
- CVE-2022-29178Cilium is open source software for providing and securing ne…8.2
- CVE-2022-29179Cilium is open source software for providing and securing ne…8.2
- CVE-2022-29180A vulnerability in which attackers could forge HTTP requests…9.8
- CVE-2022-29181Nokogiri is an open source XML and HTML library for Ruby. No…8.2
- CVE-2022-29182GoCD is a continuous delivery server. GoCD versions 19.11.0 …5.4
Are you affected by CVE-2022-29176?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
