RubySec

Providing security resources for the Ruby community

OSVDB-115091 (bundler): Bundler Gem for Ruby Redirection Remote HTTP Basic Authentication Credential Disclosure

ADVISORIES

GEM

bundler

PATCHED VERSIONS

  • >= 1.3.0.pre.8

DESCRIPTION

Bundler Gem for Ruby contains a flaw that is triggered during the redirection to other hosts. This may allow a remote attacker to gain access to HTTP basic authentication credential information.

RELATED