CVE-2022-29176 is a critical vulnerability in RubyGems.org that allowed unauthorized users to remove and replace certain Ruby gems due to a bug in the "yank" action. This high-severity vulnerability (CVSS 7.5) has a network attack vector and low privileges required, but high impact on confidentiality, integrity, and availability. While there is no evidence of active exploitation, no public exploit code, and it is not on the CISA KEV catalog, the vulnerability has garnered significant community discussion and media coverage. RubyGems.org has been patched, and users are advised to audit their Gemfile.lock for potential past abuse.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:rubygems:rubygems.org:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.