First published: Fri Jan 12 2024(Updated: )
Rubygems.org is the Ruby community's gem hosting service. Rubygems.org users with MFA enabled would normally be protected from account takeover in the case of email account takeover. However, a workaround on the forgotten password form allows an attacker to bypass the MFA requirement and takeover the account. This vulnerability has been patched in commit 0b3272a.
Credit: security-advisories@github.com
Affected Software | Affected Version | How to fix |
---|---|---|
Rubygems Rubygems.org | <2024-01-08 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.