Bundler
5 known vulnerabilities
Top Products
`Bundler` is a package for managing application dependencies in Ruby. In `bundler` versions before 2.2.33, when working
Bundler 1.16.0 through 2.2.9 and 2.2.11 through 2.2.16 sometimes chooses a dependency source based on the highest gem ve
Bundler prior to 2.1.0 uses a predictable path in /tmp/, created with insecure permissions as a storage location for gem
Bundler 1.x might allow remote attackers to inject arbitrary Ruby code into an application by leveraging a gem name coll
Frequently Asked Questions
How many CVEs affect Bundler?
Bundler has 5 CVE records in our database, including 1 critical and 2 high severity vulnerabilities.
What are the most severe Bundler vulnerabilities?
Bundler has 1 critical severity (CVSS 9.0+) and 2 high severity (CVSS 7.0-8.9) vulnerabilities. Review the list above sorted by publication date to find the most recent high-severity issues.
How can I scan for Bundler vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Bundler products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Bundler Vulnerabilities
CyberStrike scans your infrastructure for Bundler vulnerabilities and provides real-time remediation guidance.
Get Started