Geminabox Project maintains a Ruby gem hosting and repository server that, despite a narrowly focused product line, sits within development and deployment pipelines where it handles package metadata and distribution. Its observed vulnerability pattern centers on web application input-handling issues, particularly cross-site scripting and cross-site request forgery flaws that reflect the interactive nature of a package-management interface. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Geminabox Project over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-14683HIGH geminabox (aka Gem in a Box) before 0.13.7 has CSRF, as demonstrated by an unintended gem upload. | Sep 25, 2017 | 8.8 | 26 | NO | NO |
CVE-2017-16792MEDIUM Stored cross-site scripting (XSS) vulnerability in "geminabox" (Gem in a Box) before 0.13.10 allows attackers to inject arbitrary web script via the "homepage" value of a ".gemspec | Nov 13, 2017 | 6.1 | 21 | NO | NO |
CVE-2017-14506MEDIUM geminabox (aka Gem in a Box) before 0.13.6 has XSS, as demonstrated by uploading a gem file that has a crafted gem.homepage value in its .gemspec file. | Sep 25, 2017 | 5.4 | 19 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Geminabox Project.
Media articles that mention a CVE ID that affects a product developed by Geminabox Project — matched by CVE ID, not by vendor name.