Rubygems.org is the Ruby community's... CVE-2024-21654

- AV AC AU C I A
发布: 2024-01-12
修订: 2024-01-22

Rubygems.org is the Ruby community's gem hosting service. Rubygems.org users with MFA enabled would normally be protected from account takeover in the case of email account takeover. However, a workaround on the forgotten password form allows an attacker to bypass the MFA requirement and takeover the account. This vulnerability has been patched in commit 0b3272a.

0%
暂无可用Exp或PoC
当前有1条受影响产品信息