Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:30297
HistoryApr 30, 2021 - 2:34 a.m.

Dependency Confusion

2021-04-3002:34:33
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
27

0.01 Low

EPSS

Percentile

83.4%

Bundler is vulnerable to dependency confusion. The way of choosing a dependency source based on the highest gem version number by the package installer results in pulling a malicious gem from a public repository instead of its intended private gem even if it is a dependency of another private gem.