CVE-2022-29218 is a high-severity vulnerability affecting RubyGems.org, where an ordering error in gem upload code allowed malicious packages to temporarily replace legitimate gems in the CDN cache, specifically those with platform names ending in numbers. This flaw could lead to integrity compromise (CVSS 7.5, I:H) if an attacker successfully replaced a gem, potentially distributing malicious code to users. While the vulnerability has been patched and is believed to have never been exploited based on extensive log reviews, there is no known public exploit code, Metasploit module, or significant community discussion surrounding it.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:rubygems:rubygems.org:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.