CVE-2024-21654: rubygems.org MFA Bypass through password reset function could allow account takeover
Rubygems.org is the Ruby community's gem hosting service. Rubygems.org users with MFA enabled would normally be protected from account takeover in the case of email account takeover. However, a workaround on the forgotten password form allows an attacker to bypass the MFA requirement and takeover the account. This vulnerability has been patched in commit 0b3272a.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
rubygems.orgto a version that resolves this vulnerability.Patch 0b3272a
Event History
Frequently Asked Questions
What is the severity of CVE-2024-21654?
CVE-2024-21654 has a high severity rating due to the potential for account takeover despite MFA being enabled.
How do I fix CVE-2024-21654?
To fix CVE-2024-21654, it is recommended to update RubyGems to a version later than 2024-01-08.
Who is affected by CVE-2024-21654?
Users of rubygems.org who have multi-factor authentication (MFA) enabled are affected by CVE-2024-21654.
What type of vulnerability is CVE-2024-21654?
CVE-2024-21654 is classified as a security vulnerability related to authentication bypass.
Can CVE-2024-21654 be exploited remotely?
Yes, CVE-2024-21654 can potentially be exploited remotely through the forgotten password form on rubygems.org.