Lucene search

K
nvd[email protected]NVD:CVE-2016-7954
HistoryDec 22, 2016 - 10:59 p.m.

CVE-2016-7954

2016-12-2222:59:00
CWE-94
web.nvd.nist.gov

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

9.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

9.5 High

AI Score

Confidence

High

0.009 Low

EPSS

Percentile

82.6%

Bundler 1.x might allow remote attackers to inject arbitrary Ruby code into an application by leveraging a gem name collision on a secondary source. NOTE: this might overlap CVE-2013-0334.

Affected configurations

NVD
Node
bundlerbundlerMatch1.0.0
OR
bundlerbundlerMatch1.0.0beta1
OR
bundlerbundlerMatch1.0.0beta10
OR
bundlerbundlerMatch1.0.0beta6
OR
bundlerbundlerMatch1.0.0beta7
OR
bundlerbundlerMatch1.0.0beta8
OR
bundlerbundlerMatch1.0.0beta9
OR
bundlerbundlerMatch1.0.0rc1
OR
bundlerbundlerMatch1.0.0rc2
OR
bundlerbundlerMatch1.0.0rc3
OR
bundlerbundlerMatch1.0.0rc4
OR
bundlerbundlerMatch1.0.0rc5
OR
bundlerbundlerMatch1.0.0rc6
OR
bundlerbundlerMatch1.0.1
OR
bundlerbundlerMatch1.0.2
OR
bundlerbundlerMatch1.0.3
OR
bundlerbundlerMatch1.0.4
OR
bundlerbundlerMatch1.0.5
OR
bundlerbundlerMatch1.0.6
OR
bundlerbundlerMatch1.0.7
OR
bundlerbundlerMatch1.0.8
OR
bundlerbundlerMatch1.0.9
OR
bundlerbundlerMatch1.0.10
OR
bundlerbundlerMatch1.0.11
OR
bundlerbundlerMatch1.0.12
OR
bundlerbundlerMatch1.0.13
OR
bundlerbundlerMatch1.0.14
OR
bundlerbundlerMatch1.0.15
OR
bundlerbundlerMatch1.0.16
OR
bundlerbundlerMatch1.0.17
OR
bundlerbundlerMatch1.0.18
OR
bundlerbundlerMatch1.0.19rc
OR
bundlerbundlerMatch1.0.20
OR
bundlerbundlerMatch1.0.20rc
OR
bundlerbundlerMatch1.0.21
OR
bundlerbundlerMatch1.0.21rc
OR
bundlerbundlerMatch1.1pre
OR
bundlerbundlerMatch1.1pre1
OR
bundlerbundlerMatch1.1pre10
OR
bundlerbundlerMatch1.1pre2
OR
bundlerbundlerMatch1.1pre3
OR
bundlerbundlerMatch1.1pre4
OR
bundlerbundlerMatch1.1pre5
OR
bundlerbundlerMatch1.1pre6
OR
bundlerbundlerMatch1.1pre7
OR
bundlerbundlerMatch1.1pre8
OR
bundlerbundlerMatch1.1pre9
OR
bundlerbundlerMatch1.1rc
OR
bundlerbundlerMatch1.1rc2
OR
bundlerbundlerMatch1.1rc3
OR
bundlerbundlerMatch1.1rc4
OR
bundlerbundlerMatch1.1rc5
OR
bundlerbundlerMatch1.1rc6
OR
bundlerbundlerMatch1.1rc7
OR
bundlerbundlerMatch1.1rc8
OR
bundlerbundlerMatch1.1.0
OR
bundlerbundlerMatch1.1.1
OR
bundlerbundlerMatch1.1.2
OR
bundlerbundlerMatch1.1.3
OR
bundlerbundlerMatch1.1.4
OR
bundlerbundlerMatch1.1.5
OR
bundlerbundlerMatch1.2.0
OR
bundlerbundlerMatch1.2.0pre
OR
bundlerbundlerMatch1.2.0pre1
OR
bundlerbundlerMatch1.2.0rc
OR
bundlerbundlerMatch1.2.0rc2
OR
bundlerbundlerMatch1.2.1
OR
bundlerbundlerMatch1.2.2
OR
bundlerbundlerMatch1.2.3
OR
bundlerbundlerMatch1.2.4
OR
bundlerbundlerMatch1.2.5
OR
bundlerbundlerMatch1.3.0
OR
bundlerbundlerMatch1.3.0pre
OR
bundlerbundlerMatch1.3.0pre2
OR
bundlerbundlerMatch1.3.0pre3
OR
bundlerbundlerMatch1.3.0pre4
OR
bundlerbundlerMatch1.3.0pre5
OR
bundlerbundlerMatch1.3.0pre6
OR
bundlerbundlerMatch1.3.0pre7
OR
bundlerbundlerMatch1.3.0pre8
OR
bundlerbundlerMatch1.3.1
OR
bundlerbundlerMatch1.3.2
OR
bundlerbundlerMatch1.3.3
OR
bundlerbundlerMatch1.3.4
OR
bundlerbundlerMatch1.3.5
OR
bundlerbundlerMatch1.3.6
OR
bundlerbundlerMatch1.4.0pre1
OR
bundlerbundlerMatch1.4.0rc1
OR
bundlerbundlerMatch1.5.0
OR
bundlerbundlerMatch1.5.0rc1
OR
bundlerbundlerMatch1.5.0rc2
OR
bundlerbundlerMatch1.5.1
OR
bundlerbundlerMatch1.5.2
OR
bundlerbundlerMatch1.5.3
OR
bundlerbundlerMatch1.6.0
OR
bundlerbundlerMatch1.6.1
OR
bundlerbundlerMatch1.6.2
OR
bundlerbundlerMatch1.6.3
OR
bundlerbundlerMatch1.6.4
OR
bundlerbundlerMatch1.6.5
OR
bundlerbundlerMatch1.6.6
OR
bundlerbundlerMatch1.6.7
OR
bundlerbundlerMatch1.7.0
OR
bundlerbundlerMatch1.7.1
OR
bundlerbundlerMatch1.7.2
OR
bundlerbundlerMatch1.7.3
OR
bundlerbundlerMatch1.7.4
OR
bundlerbundlerMatch1.7.5
OR
bundlerbundlerMatch1.7.6
OR
bundlerbundlerMatch1.7.7
OR
bundlerbundlerMatch1.7.8
OR
bundlerbundlerMatch1.7.9
OR
bundlerbundlerMatch1.7.10
OR
bundlerbundlerMatch1.7.11
OR
bundlerbundlerMatch1.7.12
OR
bundlerbundlerMatch1.7.13
OR
bundlerbundlerMatch1.7.14
OR
bundlerbundlerMatch1.7.15
OR
bundlerbundlerMatch1.8.0
OR
bundlerbundlerMatch1.8.0pre
OR
bundlerbundlerMatch1.8.0rc
OR
bundlerbundlerMatch1.8.1
OR
bundlerbundlerMatch1.8.2
OR
bundlerbundlerMatch1.8.3
OR
bundlerbundlerMatch1.8.4
OR
bundlerbundlerMatch1.8.5
OR
bundlerbundlerMatch1.8.6
OR
bundlerbundlerMatch1.8.7
OR
bundlerbundlerMatch1.8.8
OR
bundlerbundlerMatch1.8.9
OR
bundlerbundlerMatch1.9.0
OR
bundlerbundlerMatch1.9.0pre
OR
bundlerbundlerMatch1.9.0pre1
OR
bundlerbundlerMatch1.9.0rc
OR
bundlerbundlerMatch1.9.1
OR
bundlerbundlerMatch1.9.2
OR
bundlerbundlerMatch1.9.3
OR
bundlerbundlerMatch1.9.4
OR
bundlerbundlerMatch1.9.5
OR
bundlerbundlerMatch1.9.6
OR
bundlerbundlerMatch1.9.7
OR
bundlerbundlerMatch1.9.8
OR
bundlerbundlerMatch1.9.9
OR
bundlerbundlerMatch1.9.10
OR
bundlerbundlerMatch1.10.0
OR
bundlerbundlerMatch1.10.0pre
OR
bundlerbundlerMatch1.10.0pre1
OR
bundlerbundlerMatch1.10.0pre2
OR
bundlerbundlerMatch1.10.0rc
OR
bundlerbundlerMatch1.10.1
OR
bundlerbundlerMatch1.10.2
OR
bundlerbundlerMatch1.10.3
OR
bundlerbundlerMatch1.10.4
OR
bundlerbundlerMatch1.10.5
OR
bundlerbundlerMatch1.10.6
OR
bundlerbundlerMatch1.11.0
OR
bundlerbundlerMatch1.11.0pre1
OR
bundlerbundlerMatch1.11.0pre2
OR
bundlerbundlerMatch1.11.1
OR
bundlerbundlerMatch1.11.2
OR
bundlerbundlerMatch1.12.0
OR
bundlerbundlerMatch1.12.0pre1
OR
bundlerbundlerMatch1.12.0pre2
OR
bundlerbundlerMatch1.12.0rc
OR
bundlerbundlerMatch1.12.0rc2
OR
bundlerbundlerMatch1.12.0rc3
OR
bundlerbundlerMatch1.12.0rc4
OR
bundlerbundlerMatch1.12.1
OR
bundlerbundlerMatch1.12.2
OR
bundlerbundlerMatch1.12.3
OR
bundlerbundlerMatch1.12.4
OR
bundlerbundlerMatch1.12.5
OR
bundlerbundlerMatch1.12.6
OR
bundlerbundlerMatch1.13.0
OR
bundlerbundlerMatch1.13.0pre1
OR
bundlerbundlerMatch1.13.0rc1
OR
bundlerbundlerMatch1.13.0rc2
OR
bundlerbundlerMatch1.13.1
OR
bundlerbundlerMatch1.13.2
OR
bundlerbundlerMatch1.13.3
OR
bundlerbundlerMatch1.13.4
OR
bundlerbundlerMatch1.13.5
OR
bundlerbundlerMatch1.13.6

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

9.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

9.5 High

AI Score

Confidence

High

0.009 Low

EPSS

Percentile

82.6%