← Back

CVE-2024-21654

nvd nist
Published: Jan 12, 2024Modified: Nov 21, 2024

JSON object

Loading...
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD

Description

Rubygems.org is the Ruby community's gem hosting service. Rubygems.org users with MFA enabled would normally be protected from account takeover in the case of email account takeover. However, a workaround on the forgotten password form allows an attacker to bypass the MFA requirement and takeover the account. This vulnerability has been patched in commit 0b3272a.

Affected (1)

1 product
Rubygems.org
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 2024-01-08

References (4)

Timeline

No history available yet.