bundler is vulnerable to Path Traversal
62
Medium Risk
Bundler builds compact-index cache file paths by joining a gem name from remote index data into the local cache directory without checking that the name is a safe path component. A malicious or compromised index or mirror can supply a gem name that contains path traversal segments, so Bundler writes cache files outside the intended cache directory. The fix checks gem names before building those cache paths.
You are affected if you are using a version that falls within the vulnerable range and Bundler fetches gem metadata from an untrusted or compromised index or mirror.
bundler is vulnerable to Path Traversal in versions 1.17.2 - 4.0.17.
Upgrade the bundler library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant