bundler
Security Risk Profile
82
/100
criticalSecurity Risk Score
Comprehensive risk assessment based on 6 vulnerabilities, EPSS scores, exploitation status, and remediation availability.
📅 Data spans from October 31, 2014 to present
6
Total CVEs
4
Critical+High
0
Exploited
0
Unpatched
Threat Assessment
Avg CVSS
7.5
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
0
Critical/High
Risk Level
82/100
critical
Severity Distribution
Critical
2High
2Medium
2Low
0Exploit Likelihood
>50% chance
020-50%
05-20%
0<5%
0Age Distribution
Common Weaknesses (CWE)
1
Command Injection
1
2
Code Injection
1
3
Input Validation
1
Most Affected Products
1. Bundler Bundler184
2. Bundler Bundler Ruby5
3. Fedoraproject Fedora4
4. rubygems/bundler2
5. redhat/rubygem-bundler2
Recent Vulnerabilities
See more →CVE-2021-43809
CVSS 9.3critical
Local Code Execution through Argument Injection via dash leading git url parameter in Gemfile
12/8/2021
CVE-2020-36327
CVSS 8.8high
2/9/2021
CVE-2019-3881
CVSS 7.8high
5/23/2018
CVE-2016-7954
CVSS 9.8critical
10/5/2016
REDHAT-BUG-1381951
CVSS 4.0medium
10/5/2016🔧 No Patch
CVE-2013-0334
CVSS 5.0medium
10/31/2014🔧 No Patch
Monitor bundler in Real-Time
Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.