CVE Database
/

CVE-2019-3881

Back to search

CVE-2019-3881

Published: Sep 4, 2020

Modified: Aug 4, 2024

PUBLISHED

Description

Bundler prior to 2.1.0 uses a predictable path in /tmp/, created with insecure permissions as a storage location for gems, if locations under the user's home directory are not available. If Bundler is used in a scenario where the user does not have a writable home directory, an attacker could place malicious code in this directory that would be later loaded and executed.

VendorProductVersions

n/a

rubygem-bundler

affected
bundler versions before 2.1.0

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now