Improper verification of signatures in tarball allows to install mis-signed gem when tarball contain multiple gem signatures.
Upstream fix:
https://github.com/rubygems/rubygems/commit/f5042b879259b1f1ce95a0c5082622c646376693
External References:
https://www.ruby-lang.org/en/news/2018/02/17/multiple-vulnerabilities-in-rubygems/
Last updated 18 August 2025
Last updated 18 August 2025
Last updated 18 August 2025
Cross-site scripting vulnerability in homepage attribute when displayed via gem server was found.
Upstream fix:
https://github.com/rubygems/rubygems/commit/66a28b9275551384fdab45f3591a82d6b59952cb
External References:
https://www.ruby-lang.org/en/news/2018/02/17/multiple-vulnerabilities-in-rubygems/
Last updated 18 August 2025
Last updated 18 August 2025