CVE-2021-43809 is a code execution vulnerability in Bundler versions prior to 2.2.33, a Ruby dependency manager. It arises when processing a crafted Gemfile that uses a Git dependency with a specially formatted URL starting with a dash, which can be misinterpreted as an optional argument to Git commands. This allows for arbitrary code execution, leading to potential system takeover, but requires significant user interaction to exploit. The vulnerability has a CVSS score of 7.3 (High) due to its impact, but its exploitability is low, and there is no evidence of active exploitation or publicly available exploit code.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.2.33CPE matchmatch criteria | cpe:2.3:a:bundler:bundler:*:*:*:*:*:ruby:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.