CVE-2022-36073
Last modified
CVE-2022-36073 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. RubyGems.org is the Ruby community gem host. A bug in password & email change confirmation code allowed an attacker to change their RubyGems.org account's email to an unowned email address. EPSS estimates a 0.81% chance of exploitation in the next 30 days.
Description
RubyGems.org is the Ruby community gem host. A bug in password & email change confirmation code allowed an attacker to change their RubyGems.org account's email to an unowned email address. Having access to an account whose email has been changed could enable an attacker to save API keys for that account, and when a legitimate user attempts to create an account with their email (and has to reset password to gain access) and is granted access to other gems, the attacker would then be able to publish and yank versions of those gems. Commit number 90c9e6aac2d91518b479c51d48275c57de492d4d contains a patch for this issue.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Rubygems | Rubygems | < 2022-08-31 |
References
- https://github.com/rubygems/rubygems.org/commit/90c9e6aac2d91518b479c51d48275c57de492d4dPatch, Third Party Advisory
- https://github.com/rubygems/rubygems.org/security/advisories/GHSA-8qpf-wf2p-25vgPatch, Third Party Advisory
- https://github.com/rubygems/rubygems.org/commit/90c9e6aac2d91518b479c51d48275c57de492d4dPatch, Third Party Advisory
- https://github.com/rubygems/rubygems.org/security/advisories/GHSA-8qpf-wf2p-25vgPatch, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-36073?
How severe is CVE-2022-36073?
How do I fix CVE-2022-36073?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2022
- CVE-2022-36068Discourse is an open source discussion platform. In versions…4.3
- CVE-2022-36069Poetry is a dependency manager for Python. When handling dep…7.3
- CVE-2022-3607Failure to Sanitize Special Elements into a Different Plane …6
- CVE-2022-36070Poetry is a dependency manager for Python. To handle depende…7.3
- CVE-2022-36071SFTPGo is configurable SFTP server with optional HTTP/S, FTP…8.1
- CVE-2022-36072SilverwareGames.io is a social network for users to play vid…5.9
- CVE-2022-36074Nextcloud server is an open source personal cloud product. A…7.5
- CVE-2022-36075Nextcloud files access control is a nextcloud app to manage …4.3
- CVE-2022-36076NodeBB Forum Software is powered by Node.js and supports eit…7.5
- CVE-2022-36077The Electron framework enables writing cross-platform deskto…6.1
- CVE-2022-36078Binary provides encoding/decoding in Borsh and other formats…7.5
- CVE-2022-36079Parse Server is an open source backend that can be deployed …7.5
Are you affected by CVE-2022-36073?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
