Description
RubyGems version Ruby 2.2 series: 2.2.9 and earlier, Ruby 2.3 series: 2.3.6 and earlier, Ruby 2.4 series: 2.4.3 and earlier, Ruby 2.5 series: 2.5.0 and earlier, prior to trunk revision 62422 contains a Improper Verification of Cryptographic Signature vulnerability in package.rb that can result in a mis-signed gem could be installed, as the tarball would contain multiple gem signatures.. This vulnerability appears to have been fixed in 2.7.6.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-1336-1 | rubygems security update |
Debian DLA |
DLA-1337-1 | jruby security update |
Debian DLA |
DLA-1358-1 | ruby1.9.1 security update |
Debian DLA |
DLA-1421-1 | ruby2.1 security update |
Debian DLA |
DLA-1796-1 | jruby security update |
Debian DSA |
DSA-4219-1 | jruby security update |
Debian DSA |
DSA-4259-1 | ruby2.3 security update |
EUVD |
EUVD-2022-4540 | RubyGems version Ruby 2.2 series: 2.2.9 and earlier, Ruby 2.3 series: 2.3.6 and earlier, Ruby 2.4 series: 2.4.3 and earlier, Ruby 2.5 series: 2.5.0 and earlier, prior to trunk revision 62422 contains a Improper Verification of Cryptographic Signature vulnerability in package.rb that can result in a mis-signed gem could be installed, as the tarball would contain multiple gem signatures.. This vulnerability appears to have been fixed in 2.7.6. |
Github GHSA |
GHSA-mc6j-h948-v2p6 | RubyGems Improper Verification of Cryptographic Signature vulnerability |
Ubuntu USN |
USN-3621-1 | Ruby vulnerabilities |
References
History
Sun, 13 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-05T12:33:49.167Z
Reserved: 2018-02-21T00:00:00.000Z
Link: CVE-2018-1000076
No data.
Status : Modified
Published: 2018-03-13T15:29:00.613
Modified: 2024-11-21T03:39:35.100
Link: CVE-2018-1000076
OpenCVE Enrichment
No data.
Weaknesses
Debian DLA
Debian DSA
EUVD
Github GHSA
Ubuntu USN