geminabox
A private gem hosting and/or caching app, with client side gem push style functionality. Web UI is provided.
Activity
- Latest release
- 3mo ago
- Total releases
- 75
- Cadence
- ~14 days
- Last 12 months
- 3
Reach
- Stars
- —
Details
- License
- MIT
- First release
- Jan 07, 2010
| Version | Released | |
|---|---|---|
3.1.0
minor
|
3.1.0
minor
Dependencies (7)
Changelog
Compare changes
|
|
3.0.0
major
|
3.0.0
major
Dependencies (7)
Changelog
Compare changes
|
|
2.2.0
minor
| ||
2.1.0
minor
| ||
2.1.0.rc.1
pre
| ||
2.0.0.rc.1
pre
| ||
2.0.0
major
| ||
1.5.0.rc.1
pre
| ||
1.5.0
minor
| ||
1.4.3.rc
pre
| ||
1.4.3
patch
| ||
1.3.1
patch
| ||
1.4.1
patch
| ||
1.4.0
minor
| ||
1.3.0
minor
| ||
1.2.0
minor
| ||
1.1.1
patch
| ||
1.1.0
minor
| ||
1.0.1
patch
| ||
1.0.0
major
| ||
0.13.15
patch
| ||
0.13.14
patch
| ||
0.13.13
patch
| ||
0.13.11
patch
| ||
0.13.10
patch
| ||
0.13.9
patch
1 CVE
CVE-2017-16792
GHSA-653m-r33x-39ff
Nov 29, 2017
Geminabox contains Cross-site Scripting
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Stored cross-site scripting (XSS) vulnerability in "geminabox" (Gem in a Box) before 0.13.10 allows attackers to inject arbitrary web script via the "homepage" value of a ".gemspec" file, related to views/gem.erb and views/index.erb. Affected versions
0.1.0
0.10.0
0.10.1
0.11.0
0.11.1
0.12.0
0.12.1
0.12.2
0.12.3
0.12.4
0.13.0
0.13.1
+ 38 more Show less
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.13.7
0.13.8
0.13.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.13
0.2.14
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.pre1
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.1pre1
0.7.0
0.8.0
0.9.0
Fixed in
0.13.10
References Updated Nov 08, 2023 · Source: OSV.dev | ||
0.13.8
patch
1 CVE
CVE-2017-16792
GHSA-653m-r33x-39ff
Nov 29, 2017
Geminabox contains Cross-site Scripting
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Stored cross-site scripting (XSS) vulnerability in "geminabox" (Gem in a Box) before 0.13.10 allows attackers to inject arbitrary web script via the "homepage" value of a ".gemspec" file, related to views/gem.erb and views/index.erb. Affected versions
0.1.0
0.10.0
0.10.1
0.11.0
0.11.1
0.12.0
0.12.1
0.12.2
0.12.3
0.12.4
0.13.0
0.13.1
+ 38 more Show less
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.13.7
0.13.8
0.13.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.13
0.2.14
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.pre1
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.1pre1
0.7.0
0.8.0
0.9.0
Fixed in
0.13.10
References Updated Nov 08, 2023 · Source: OSV.dev | ||
0.13.7
patch
1 CVE
CVE-2017-16792
GHSA-653m-r33x-39ff
Nov 29, 2017
Geminabox contains Cross-site Scripting
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Stored cross-site scripting (XSS) vulnerability in "geminabox" (Gem in a Box) before 0.13.10 allows attackers to inject arbitrary web script via the "homepage" value of a ".gemspec" file, related to views/gem.erb and views/index.erb. Affected versions
0.1.0
0.10.0
0.10.1
0.11.0
0.11.1
0.12.0
0.12.1
0.12.2
0.12.3
0.12.4
0.13.0
0.13.1
+ 38 more Show less
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.13.7
0.13.8
0.13.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.13
0.2.14
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.pre1
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.1pre1
0.7.0
0.8.0
0.9.0
Fixed in
0.13.10
References Updated Nov 08, 2023 · Source: OSV.dev | ||
0.13.6
patch
2 CVEs
CVE-2017-14683
GHSA-qwv2-2x8g-g43g
May 13, 2022
Gem in a Box vulnerable to Cross-site Request Forgery
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
geminabox (aka Gem in a Box) before 0.13.7 has CSRF, as demonstrated by an unintended gem upload. Affected versions
0.1.0
0.10.0
0.10.1
0.11.0
0.11.1
0.12.0
0.12.1
0.12.2
0.12.3
0.12.4
0.13.0
0.13.1
+ 35 more Show less
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.2.0
0.2.1
0.2.10
0.2.11
0.2.13
0.2.14
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.pre1
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.1pre1
0.7.0
0.8.0
0.9.0
Fixed in
0.13.7
References
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2017-16792
GHSA-653m-r33x-39ff
Nov 29, 2017
Geminabox contains Cross-site Scripting
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Stored cross-site scripting (XSS) vulnerability in "geminabox" (Gem in a Box) before 0.13.10 allows attackers to inject arbitrary web script via the "homepage" value of a ".gemspec" file, related to views/gem.erb and views/index.erb. Affected versions
0.1.0
0.10.0
0.10.1
0.11.0
0.11.1
0.12.0
0.12.1
0.12.2
0.12.3
0.12.4
0.13.0
0.13.1
+ 38 more Show less
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.13.7
0.13.8
0.13.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.13
0.2.14
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.pre1
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.1pre1
0.7.0
0.8.0
0.9.0
Fixed in
0.13.10
References Updated Nov 08, 2023 · Source: OSV.dev | ||
0.13.5
patch
3 CVEs
CVE-2017-14506
GHSA-98hq-3qvg-pg78
May 13, 2022
Gem in a Box vulnerable to Cross-site Scripting
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
geminabox (aka Gem in a Box) before 0.13.6 is vulnerable to Cross-site Scripting (XSS), as demonstrated by uploading a gem file that has a crafted gem.homepage value in its .gemspec file. Affected versions
0.1.0
0.10.0
0.10.1
0.11.0
0.11.1
0.12.0
0.12.1
0.12.2
0.12.3
0.12.4
0.13.0
0.13.1
+ 34 more Show less
0.13.2
0.13.3
0.13.4
0.13.5
0.2.0
0.2.1
0.2.10
0.2.11
0.2.13
0.2.14
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.pre1
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.1pre1
0.7.0
0.8.0
0.9.0
Fixed in
0.13.6
References
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2017-14683
GHSA-qwv2-2x8g-g43g
May 13, 2022
Gem in a Box vulnerable to Cross-site Request Forgery
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
geminabox (aka Gem in a Box) before 0.13.7 has CSRF, as demonstrated by an unintended gem upload. Affected versions
0.1.0
0.10.0
0.10.1
0.11.0
0.11.1
0.12.0
0.12.1
0.12.2
0.12.3
0.12.4
0.13.0
0.13.1
+ 35 more Show less
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.2.0
0.2.1
0.2.10
0.2.11
0.2.13
0.2.14
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.pre1
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.1pre1
0.7.0
0.8.0
0.9.0
Fixed in
0.13.7
References
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2017-16792
GHSA-653m-r33x-39ff
Nov 29, 2017
Geminabox contains Cross-site Scripting
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Stored cross-site scripting (XSS) vulnerability in "geminabox" (Gem in a Box) before 0.13.10 allows attackers to inject arbitrary web script via the "homepage" value of a ".gemspec" file, related to views/gem.erb and views/index.erb. Affected versions
0.1.0
0.10.0
0.10.1
0.11.0
0.11.1
0.12.0
0.12.1
0.12.2
0.12.3
0.12.4
0.13.0
0.13.1
+ 38 more Show less
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.13.7
0.13.8
0.13.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.13
0.2.14
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.pre1
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.1pre1
0.7.0
0.8.0
0.9.0
Fixed in
0.13.10
References Updated Nov 08, 2023 · Source: OSV.dev | ||
0.13.4
patch
3 CVEs
CVE-2017-14506
GHSA-98hq-3qvg-pg78
May 13, 2022
Gem in a Box vulnerable to Cross-site Scripting
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
geminabox (aka Gem in a Box) before 0.13.6 is vulnerable to Cross-site Scripting (XSS), as demonstrated by uploading a gem file that has a crafted gem.homepage value in its .gemspec file. Affected versions
0.1.0
0.10.0
0.10.1
0.11.0
0.11.1
0.12.0
0.12.1
0.12.2
0.12.3
0.12.4
0.13.0
0.13.1
+ 34 more Show less
0.13.2
0.13.3
0.13.4
0.13.5
0.2.0
0.2.1
0.2.10
0.2.11
0.2.13
0.2.14
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.pre1
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.1pre1
0.7.0
0.8.0
0.9.0
Fixed in
0.13.6
References
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2017-14683
GHSA-qwv2-2x8g-g43g
May 13, 2022
Gem in a Box vulnerable to Cross-site Request Forgery
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
geminabox (aka Gem in a Box) before 0.13.7 has CSRF, as demonstrated by an unintended gem upload. Affected versions
0.1.0
0.10.0
0.10.1
0.11.0
0.11.1
0.12.0
0.12.1
0.12.2
0.12.3
0.12.4
0.13.0
0.13.1
+ 35 more Show less
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.2.0
0.2.1
0.2.10
0.2.11
0.2.13
0.2.14
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.pre1
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.1pre1
0.7.0
0.8.0
0.9.0
Fixed in
0.13.7
References
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2017-16792
GHSA-653m-r33x-39ff
Nov 29, 2017
Geminabox contains Cross-site Scripting
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Stored cross-site scripting (XSS) vulnerability in "geminabox" (Gem in a Box) before 0.13.10 allows attackers to inject arbitrary web script via the "homepage" value of a ".gemspec" file, related to views/gem.erb and views/index.erb. Affected versions
0.1.0
0.10.0
0.10.1
0.11.0
0.11.1
0.12.0
0.12.1
0.12.2
0.12.3
0.12.4
0.13.0
0.13.1
+ 38 more Show less
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.13.7
0.13.8
0.13.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.13
0.2.14
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.pre1
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.1pre1
0.7.0
0.8.0
0.9.0
Fixed in
0.13.10
References Updated Nov 08, 2023 · Source: OSV.dev | ||
0.13.3
patch
3 CVEs
CVE-2017-14506
GHSA-98hq-3qvg-pg78
May 13, 2022
Gem in a Box vulnerable to Cross-site Scripting
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
geminabox (aka Gem in a Box) before 0.13.6 is vulnerable to Cross-site Scripting (XSS), as demonstrated by uploading a gem file that has a crafted gem.homepage value in its .gemspec file. Affected versions
0.1.0
0.10.0
0.10.1
0.11.0
0.11.1
0.12.0
0.12.1
0.12.2
0.12.3
0.12.4
0.13.0
0.13.1
+ 34 more Show less
0.13.2
0.13.3
0.13.4
0.13.5
0.2.0
0.2.1
0.2.10
0.2.11
0.2.13
0.2.14
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.pre1
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.1pre1
0.7.0
0.8.0
0.9.0
Fixed in
0.13.6
References
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2017-14683
GHSA-qwv2-2x8g-g43g
May 13, 2022
Gem in a Box vulnerable to Cross-site Request Forgery
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
geminabox (aka Gem in a Box) before 0.13.7 has CSRF, as demonstrated by an unintended gem upload. Affected versions
0.1.0
0.10.0
0.10.1
0.11.0
0.11.1
0.12.0
0.12.1
0.12.2
0.12.3
0.12.4
0.13.0
0.13.1
+ 35 more Show less
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.2.0
0.2.1
0.2.10
0.2.11
0.2.13
0.2.14
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.pre1
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.1pre1
0.7.0
0.8.0
0.9.0
Fixed in
0.13.7
References
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2017-16792
GHSA-653m-r33x-39ff
Nov 29, 2017
Geminabox contains Cross-site Scripting
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Stored cross-site scripting (XSS) vulnerability in "geminabox" (Gem in a Box) before 0.13.10 allows attackers to inject arbitrary web script via the "homepage" value of a ".gemspec" file, related to views/gem.erb and views/index.erb. Affected versions
0.1.0
0.10.0
0.10.1
0.11.0
0.11.1
0.12.0
0.12.1
0.12.2
0.12.3
0.12.4
0.13.0
0.13.1
+ 38 more Show less
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.13.7
0.13.8
0.13.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.13
0.2.14
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.pre1
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.1pre1
0.7.0
0.8.0
0.9.0
Fixed in
0.13.10
References Updated Nov 08, 2023 · Source: OSV.dev | ||
0.13.2
patch
3 CVEs
CVE-2017-14506
GHSA-98hq-3qvg-pg78
May 13, 2022
Gem in a Box vulnerable to Cross-site Scripting
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
geminabox (aka Gem in a Box) before 0.13.6 is vulnerable to Cross-site Scripting (XSS), as demonstrated by uploading a gem file that has a crafted gem.homepage value in its .gemspec file. Affected versions
0.1.0
0.10.0
0.10.1
0.11.0
0.11.1
0.12.0
0.12.1
0.12.2
0.12.3
0.12.4
0.13.0
0.13.1
+ 34 more Show less
0.13.2
0.13.3
0.13.4
0.13.5
0.2.0
0.2.1
0.2.10
0.2.11
0.2.13
0.2.14
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.pre1
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.1pre1
0.7.0
0.8.0
0.9.0
Fixed in
0.13.6
References
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2017-14683
GHSA-qwv2-2x8g-g43g
May 13, 2022
Gem in a Box vulnerable to Cross-site Request Forgery
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
geminabox (aka Gem in a Box) before 0.13.7 has CSRF, as demonstrated by an unintended gem upload. Affected versions
0.1.0
0.10.0
0.10.1
0.11.0
0.11.1
0.12.0
0.12.1
0.12.2
0.12.3
0.12.4
0.13.0
0.13.1
+ 35 more Show less
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.2.0
0.2.1
0.2.10
0.2.11
0.2.13
0.2.14
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.pre1
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.1pre1
0.7.0
0.8.0
0.9.0
Fixed in
0.13.7
References
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2017-16792
GHSA-653m-r33x-39ff
Nov 29, 2017
Geminabox contains Cross-site Scripting
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Stored cross-site scripting (XSS) vulnerability in "geminabox" (Gem in a Box) before 0.13.10 allows attackers to inject arbitrary web script via the "homepage" value of a ".gemspec" file, related to views/gem.erb and views/index.erb. Affected versions
0.1.0
0.10.0
0.10.1
0.11.0
0.11.1
0.12.0
0.12.1
0.12.2
0.12.3
0.12.4
0.13.0
0.13.1
+ 38 more Show less
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.13.7
0.13.8
0.13.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.13
0.2.14
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.pre1
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.1pre1
0.7.0
0.8.0
0.9.0
Fixed in
0.13.10
References Updated Nov 08, 2023 · Source: OSV.dev | ||
0.13.1
patch
3 CVEs
CVE-2017-14506
GHSA-98hq-3qvg-pg78
May 13, 2022
Gem in a Box vulnerable to Cross-site Scripting
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
geminabox (aka Gem in a Box) before 0.13.6 is vulnerable to Cross-site Scripting (XSS), as demonstrated by uploading a gem file that has a crafted gem.homepage value in its .gemspec file. Affected versions
0.1.0
0.10.0
0.10.1
0.11.0
0.11.1
0.12.0
0.12.1
0.12.2
0.12.3
0.12.4
0.13.0
0.13.1
+ 34 more Show less
0.13.2
0.13.3
0.13.4
0.13.5
0.2.0
0.2.1
0.2.10
0.2.11
0.2.13
0.2.14
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.pre1
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.1pre1
0.7.0
0.8.0
0.9.0
Fixed in
0.13.6
References
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2017-14683
GHSA-qwv2-2x8g-g43g
May 13, 2022
Gem in a Box vulnerable to Cross-site Request Forgery
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
geminabox (aka Gem in a Box) before 0.13.7 has CSRF, as demonstrated by an unintended gem upload. Affected versions
0.1.0
0.10.0
0.10.1
0.11.0
0.11.1
0.12.0
0.12.1
0.12.2
0.12.3
0.12.4
0.13.0
0.13.1
+ 35 more Show less
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.2.0
0.2.1
0.2.10
0.2.11
0.2.13
0.2.14
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.pre1
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.1pre1
0.7.0
0.8.0
0.9.0
Fixed in
0.13.7
References
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2017-16792
GHSA-653m-r33x-39ff
Nov 29, 2017
Geminabox contains Cross-site Scripting
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Stored cross-site scripting (XSS) vulnerability in "geminabox" (Gem in a Box) before 0.13.10 allows attackers to inject arbitrary web script via the "homepage" value of a ".gemspec" file, related to views/gem.erb and views/index.erb. Affected versions
0.1.0
0.10.0
0.10.1
0.11.0
0.11.1
0.12.0
0.12.1
0.12.2
0.12.3
0.12.4
0.13.0
0.13.1
+ 38 more Show less
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.13.7
0.13.8
0.13.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.13
0.2.14
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.pre1
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.1pre1
0.7.0
0.8.0
0.9.0
Fixed in
0.13.10
References Updated Nov 08, 2023 · Source: OSV.dev | ||
0.13.0
minor
3 CVEs
CVE-2017-14506
GHSA-98hq-3qvg-pg78
May 13, 2022
Gem in a Box vulnerable to Cross-site Scripting
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
geminabox (aka Gem in a Box) before 0.13.6 is vulnerable to Cross-site Scripting (XSS), as demonstrated by uploading a gem file that has a crafted gem.homepage value in its .gemspec file. Affected versions
0.1.0
0.10.0
0.10.1
0.11.0
0.11.1
0.12.0
0.12.1
0.12.2
0.12.3
0.12.4
0.13.0
0.13.1
+ 34 more Show less
0.13.2
0.13.3
0.13.4
0.13.5
0.2.0
0.2.1
0.2.10
0.2.11
0.2.13
0.2.14
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.pre1
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.1pre1
0.7.0
0.8.0
0.9.0
Fixed in
0.13.6
References
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2017-14683
GHSA-qwv2-2x8g-g43g
May 13, 2022
Gem in a Box vulnerable to Cross-site Request Forgery
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
geminabox (aka Gem in a Box) before 0.13.7 has CSRF, as demonstrated by an unintended gem upload. Affected versions
0.1.0
0.10.0
0.10.1
0.11.0
0.11.1
0.12.0
0.12.1
0.12.2
0.12.3
0.12.4
0.13.0
0.13.1
+ 35 more Show less
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.2.0
0.2.1
0.2.10
0.2.11
0.2.13
0.2.14
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.pre1
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.1pre1
0.7.0
0.8.0
0.9.0
Fixed in
0.13.7
References
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2017-16792
GHSA-653m-r33x-39ff
Nov 29, 2017
Geminabox contains Cross-site Scripting
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Stored cross-site scripting (XSS) vulnerability in "geminabox" (Gem in a Box) before 0.13.10 allows attackers to inject arbitrary web script via the "homepage" value of a ".gemspec" file, related to views/gem.erb and views/index.erb. Affected versions
0.1.0
0.10.0
0.10.1
0.11.0
0.11.1
0.12.0
0.12.1
0.12.2
0.12.3
0.12.4
0.13.0
0.13.1
+ 38 more Show less
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.13.7
0.13.8
0.13.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.13
0.2.14
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.pre1
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.1pre1
0.7.0
0.8.0
0.9.0
Fixed in
0.13.10
References Updated Nov 08, 2023 · Source: OSV.dev | ||
0.12.4
patch
3 CVEs
CVE-2017-14506
GHSA-98hq-3qvg-pg78
May 13, 2022
Gem in a Box vulnerable to Cross-site Scripting
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
geminabox (aka Gem in a Box) before 0.13.6 is vulnerable to Cross-site Scripting (XSS), as demonstrated by uploading a gem file that has a crafted gem.homepage value in its .gemspec file. Affected versions
0.1.0
0.10.0
0.10.1
0.11.0
0.11.1
0.12.0
0.12.1
0.12.2
0.12.3
0.12.4
0.13.0
0.13.1
+ 34 more Show less
0.13.2
0.13.3
0.13.4
0.13.5
0.2.0
0.2.1
0.2.10
0.2.11
0.2.13
0.2.14
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.pre1
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.1pre1
0.7.0
0.8.0
0.9.0
Fixed in
0.13.6
References
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2017-14683
GHSA-qwv2-2x8g-g43g
May 13, 2022
Gem in a Box vulnerable to Cross-site Request Forgery
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
geminabox (aka Gem in a Box) before 0.13.7 has CSRF, as demonstrated by an unintended gem upload. Affected versions
0.1.0
0.10.0
0.10.1
0.11.0
0.11.1
0.12.0
0.12.1
0.12.2
0.12.3
0.12.4
0.13.0
0.13.1
+ 35 more Show less
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.2.0
0.2.1
0.2.10
0.2.11
0.2.13
0.2.14
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.pre1
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.1pre1
0.7.0
0.8.0
0.9.0
Fixed in
0.13.7
References
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2017-16792
GHSA-653m-r33x-39ff
Nov 29, 2017
Geminabox contains Cross-site Scripting
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Stored cross-site scripting (XSS) vulnerability in "geminabox" (Gem in a Box) before 0.13.10 allows attackers to inject arbitrary web script via the "homepage" value of a ".gemspec" file, related to views/gem.erb and views/index.erb. Affected versions
0.1.0
0.10.0
0.10.1
0.11.0
0.11.1
0.12.0
0.12.1
0.12.2
0.12.3
0.12.4
0.13.0
0.13.1
+ 38 more Show less
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.13.7
0.13.8
0.13.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.13
0.2.14
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.pre1
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.1pre1
0.7.0
0.8.0
0.9.0
Fixed in
0.13.10
References Updated Nov 08, 2023 · Source: OSV.dev | ||
0.12.3
patch
3 CVEs
CVE-2017-14506
GHSA-98hq-3qvg-pg78
May 13, 2022
Gem in a Box vulnerable to Cross-site Scripting
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
geminabox (aka Gem in a Box) before 0.13.6 is vulnerable to Cross-site Scripting (XSS), as demonstrated by uploading a gem file that has a crafted gem.homepage value in its .gemspec file. Affected versions
0.1.0
0.10.0
0.10.1
0.11.0
0.11.1
0.12.0
0.12.1
0.12.2
0.12.3
0.12.4
0.13.0
0.13.1
+ 34 more Show less
0.13.2
0.13.3
0.13.4
0.13.5
0.2.0
0.2.1
0.2.10
0.2.11
0.2.13
0.2.14
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.pre1
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.1pre1
0.7.0
0.8.0
0.9.0
Fixed in
0.13.6
References
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2017-14683
GHSA-qwv2-2x8g-g43g
May 13, 2022
Gem in a Box vulnerable to Cross-site Request Forgery
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
geminabox (aka Gem in a Box) before 0.13.7 has CSRF, as demonstrated by an unintended gem upload. Affected versions
0.1.0
0.10.0
0.10.1
0.11.0
0.11.1
0.12.0
0.12.1
0.12.2
0.12.3
0.12.4
0.13.0
0.13.1
+ 35 more Show less
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.2.0
0.2.1
0.2.10
0.2.11
0.2.13
0.2.14
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.pre1
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.1pre1
0.7.0
0.8.0
0.9.0
Fixed in
0.13.7
References
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2017-16792
GHSA-653m-r33x-39ff
Nov 29, 2017
Geminabox contains Cross-site Scripting
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Stored cross-site scripting (XSS) vulnerability in "geminabox" (Gem in a Box) before 0.13.10 allows attackers to inject arbitrary web script via the "homepage" value of a ".gemspec" file, related to views/gem.erb and views/index.erb. Affected versions
0.1.0
0.10.0
0.10.1
0.11.0
0.11.1
0.12.0
0.12.1
0.12.2
0.12.3
0.12.4
0.13.0
0.13.1
+ 38 more Show less
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.13.7
0.13.8
0.13.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.13
0.2.14
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.pre1
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.1pre1
0.7.0
0.8.0
0.9.0
Fixed in
0.13.10
References Updated Nov 08, 2023 · Source: OSV.dev | ||
0.12.2
patch
3 CVEs
CVE-2017-14506
GHSA-98hq-3qvg-pg78
May 13, 2022
Gem in a Box vulnerable to Cross-site Scripting
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
geminabox (aka Gem in a Box) before 0.13.6 is vulnerable to Cross-site Scripting (XSS), as demonstrated by uploading a gem file that has a crafted gem.homepage value in its .gemspec file. Affected versions
0.1.0
0.10.0
0.10.1
0.11.0
0.11.1
0.12.0
0.12.1
0.12.2
0.12.3
0.12.4
0.13.0
0.13.1
+ 34 more Show less
0.13.2
0.13.3
0.13.4
0.13.5
0.2.0
0.2.1
0.2.10
0.2.11
0.2.13
0.2.14
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.pre1
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.1pre1
0.7.0
0.8.0
0.9.0
Fixed in
0.13.6
References
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2017-14683
GHSA-qwv2-2x8g-g43g
May 13, 2022
Gem in a Box vulnerable to Cross-site Request Forgery
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
geminabox (aka Gem in a Box) before 0.13.7 has CSRF, as demonstrated by an unintended gem upload. Affected versions
0.1.0
0.10.0
0.10.1
0.11.0
0.11.1
0.12.0
0.12.1
0.12.2
0.12.3
0.12.4
0.13.0
0.13.1
+ 35 more Show less
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.2.0
0.2.1
0.2.10
0.2.11
0.2.13
0.2.14
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.pre1
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.1pre1
0.7.0
0.8.0
0.9.0
Fixed in
0.13.7
References
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2017-16792
GHSA-653m-r33x-39ff
Nov 29, 2017
Geminabox contains Cross-site Scripting
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Stored cross-site scripting (XSS) vulnerability in "geminabox" (Gem in a Box) before 0.13.10 allows attackers to inject arbitrary web script via the "homepage" value of a ".gemspec" file, related to views/gem.erb and views/index.erb. Affected versions
0.1.0
0.10.0
0.10.1
0.11.0
0.11.1
0.12.0
0.12.1
0.12.2
0.12.3
0.12.4
0.13.0
0.13.1
+ 38 more Show less
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.13.7
0.13.8
0.13.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.13
0.2.14
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.pre1
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.1pre1
0.7.0
0.8.0
0.9.0
Fixed in
0.13.10
References Updated Nov 08, 2023 · Source: OSV.dev | ||
0.12.1
patch
3 CVEs
CVE-2017-14506
GHSA-98hq-3qvg-pg78
May 13, 2022
Gem in a Box vulnerable to Cross-site Scripting
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
geminabox (aka Gem in a Box) before 0.13.6 is vulnerable to Cross-site Scripting (XSS), as demonstrated by uploading a gem file that has a crafted gem.homepage value in its .gemspec file. Affected versions
0.1.0
0.10.0
0.10.1
0.11.0
0.11.1
0.12.0
0.12.1
0.12.2
0.12.3
0.12.4
0.13.0
0.13.1
+ 34 more Show less
0.13.2
0.13.3
0.13.4
0.13.5
0.2.0
0.2.1
0.2.10
0.2.11
0.2.13
0.2.14
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.pre1
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.1pre1
0.7.0
0.8.0
0.9.0
Fixed in
0.13.6
References
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2017-14683
GHSA-qwv2-2x8g-g43g
May 13, 2022
Gem in a Box vulnerable to Cross-site Request Forgery
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
geminabox (aka Gem in a Box) before 0.13.7 has CSRF, as demonstrated by an unintended gem upload. Affected versions
0.1.0
0.10.0
0.10.1
0.11.0
0.11.1
0.12.0
0.12.1
0.12.2
0.12.3
0.12.4
0.13.0
0.13.1
+ 35 more Show less
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.2.0
0.2.1
0.2.10
0.2.11
0.2.13
0.2.14
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.pre1
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.1pre1
0.7.0
0.8.0
0.9.0
Fixed in
0.13.7
References
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2017-16792
GHSA-653m-r33x-39ff
Nov 29, 2017
Geminabox contains Cross-site Scripting
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Stored cross-site scripting (XSS) vulnerability in "geminabox" (Gem in a Box) before 0.13.10 allows attackers to inject arbitrary web script via the "homepage" value of a ".gemspec" file, related to views/gem.erb and views/index.erb. Affected versions
0.1.0
0.10.0
0.10.1
0.11.0
0.11.1
0.12.0
0.12.1
0.12.2
0.12.3
0.12.4
0.13.0
0.13.1
+ 38 more Show less
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.13.7
0.13.8
0.13.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.13
0.2.14
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.pre1
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.1pre1
0.7.0
0.8.0
0.9.0
Fixed in
0.13.10
References Updated Nov 08, 2023 · Source: OSV.dev | ||
0.12.0
minor
3 CVEs
CVE-2017-14506
GHSA-98hq-3qvg-pg78
May 13, 2022
Gem in a Box vulnerable to Cross-site Scripting
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
geminabox (aka Gem in a Box) before 0.13.6 is vulnerable to Cross-site Scripting (XSS), as demonstrated by uploading a gem file that has a crafted gem.homepage value in its .gemspec file. Affected versions
0.1.0
0.10.0
0.10.1
0.11.0
0.11.1
0.12.0
0.12.1
0.12.2
0.12.3
0.12.4
0.13.0
0.13.1
+ 34 more Show less
0.13.2
0.13.3
0.13.4
0.13.5
0.2.0
0.2.1
0.2.10
0.2.11
0.2.13
0.2.14
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.pre1
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.1pre1
0.7.0
0.8.0
0.9.0
Fixed in
0.13.6
References
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2017-14683
GHSA-qwv2-2x8g-g43g
May 13, 2022
Gem in a Box vulnerable to Cross-site Request Forgery
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
geminabox (aka Gem in a Box) before 0.13.7 has CSRF, as demonstrated by an unintended gem upload. Affected versions
0.1.0
0.10.0
0.10.1
0.11.0
0.11.1
0.12.0
0.12.1
0.12.2
0.12.3
0.12.4
0.13.0
0.13.1
+ 35 more Show less
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.2.0
0.2.1
0.2.10
0.2.11
0.2.13
0.2.14
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.pre1
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.1pre1
0.7.0
0.8.0
0.9.0
Fixed in
0.13.7
References
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2017-16792
GHSA-653m-r33x-39ff
Nov 29, 2017
Geminabox contains Cross-site Scripting
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Stored cross-site scripting (XSS) vulnerability in "geminabox" (Gem in a Box) before 0.13.10 allows attackers to inject arbitrary web script via the "homepage" value of a ".gemspec" file, related to views/gem.erb and views/index.erb. Affected versions
0.1.0
0.10.0
0.10.1
0.11.0
0.11.1
0.12.0
0.12.1
0.12.2
0.12.3
0.12.4
0.13.0
0.13.1
+ 38 more Show less
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.13.7
0.13.8
0.13.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.13
0.2.14
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.pre1
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.1pre1
0.7.0
0.8.0
0.9.0
Fixed in
0.13.10
References Updated Nov 08, 2023 · Source: OSV.dev | ||
0.11.1
patch
3 CVEs
CVE-2017-14506
GHSA-98hq-3qvg-pg78
May 13, 2022
Gem in a Box vulnerable to Cross-site Scripting
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
geminabox (aka Gem in a Box) before 0.13.6 is vulnerable to Cross-site Scripting (XSS), as demonstrated by uploading a gem file that has a crafted gem.homepage value in its .gemspec file. Affected versions
0.1.0
0.10.0
0.10.1
0.11.0
0.11.1
0.12.0
0.12.1
0.12.2
0.12.3
0.12.4
0.13.0
0.13.1
+ 34 more Show less
0.13.2
0.13.3
0.13.4
0.13.5
0.2.0
0.2.1
0.2.10
0.2.11
0.2.13
0.2.14
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.pre1
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.1pre1
0.7.0
0.8.0
0.9.0
Fixed in
0.13.6
References
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2017-14683
GHSA-qwv2-2x8g-g43g
May 13, 2022
Gem in a Box vulnerable to Cross-site Request Forgery
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
geminabox (aka Gem in a Box) before 0.13.7 has CSRF, as demonstrated by an unintended gem upload. Affected versions
0.1.0
0.10.0
0.10.1
0.11.0
0.11.1
0.12.0
0.12.1
0.12.2
0.12.3
0.12.4
0.13.0
0.13.1
+ 35 more Show less
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.2.0
0.2.1
0.2.10
0.2.11
0.2.13
0.2.14
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.pre1
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.1pre1
0.7.0
0.8.0
0.9.0
Fixed in
0.13.7
References
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2017-16792
GHSA-653m-r33x-39ff
Nov 29, 2017
Geminabox contains Cross-site Scripting
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Stored cross-site scripting (XSS) vulnerability in "geminabox" (Gem in a Box) before 0.13.10 allows attackers to inject arbitrary web script via the "homepage" value of a ".gemspec" file, related to views/gem.erb and views/index.erb. Affected versions
0.1.0
0.10.0
0.10.1
0.11.0
0.11.1
0.12.0
0.12.1
0.12.2
0.12.3
0.12.4
0.13.0
0.13.1
+ 38 more Show less
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.13.7
0.13.8
0.13.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.13
0.2.14
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.pre1
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.1pre1
0.7.0
0.8.0
0.9.0
Fixed in
0.13.10
References Updated Nov 08, 2023 · Source: OSV.dev | ||
0.11.0
minor
3 CVEs
CVE-2017-14506
GHSA-98hq-3qvg-pg78
May 13, 2022
Gem in a Box vulnerable to Cross-site Scripting
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
geminabox (aka Gem in a Box) before 0.13.6 is vulnerable to Cross-site Scripting (XSS), as demonstrated by uploading a gem file that has a crafted gem.homepage value in its .gemspec file. Affected versions
0.1.0
0.10.0
0.10.1
0.11.0
0.11.1
0.12.0
0.12.1
0.12.2
0.12.3
0.12.4
0.13.0
0.13.1
+ 34 more Show less
0.13.2
0.13.3
0.13.4
0.13.5
0.2.0
0.2.1
0.2.10
0.2.11
0.2.13
0.2.14
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.pre1
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.1pre1
0.7.0
0.8.0
0.9.0
Fixed in
0.13.6
References
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2017-14683
GHSA-qwv2-2x8g-g43g
May 13, 2022
Gem in a Box vulnerable to Cross-site Request Forgery
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
geminabox (aka Gem in a Box) before 0.13.7 has CSRF, as demonstrated by an unintended gem upload. Affected versions
0.1.0
0.10.0
0.10.1
0.11.0
0.11.1
0.12.0
0.12.1
0.12.2
0.12.3
0.12.4
0.13.0
0.13.1
+ 35 more Show less
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.2.0
0.2.1
0.2.10
0.2.11
0.2.13
0.2.14
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.pre1
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.1pre1
0.7.0
0.8.0
0.9.0
Fixed in
0.13.7
References
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2017-16792
GHSA-653m-r33x-39ff
Nov 29, 2017
Geminabox contains Cross-site Scripting
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Stored cross-site scripting (XSS) vulnerability in "geminabox" (Gem in a Box) before 0.13.10 allows attackers to inject arbitrary web script via the "homepage" value of a ".gemspec" file, related to views/gem.erb and views/index.erb. Affected versions
0.1.0
0.10.0
0.10.1
0.11.0
0.11.1
0.12.0
0.12.1
0.12.2
0.12.3
0.12.4
0.13.0
0.13.1
+ 38 more Show less
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.13.7
0.13.8
0.13.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.13
0.2.14
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.pre1
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.1pre1
0.7.0
0.8.0
0.9.0
Fixed in
0.13.10
References Updated Nov 08, 2023 · Source: OSV.dev | ||
0.10.1
patch
3 CVEs
CVE-2017-14506
GHSA-98hq-3qvg-pg78
May 13, 2022
Gem in a Box vulnerable to Cross-site Scripting
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
geminabox (aka Gem in a Box) before 0.13.6 is vulnerable to Cross-site Scripting (XSS), as demonstrated by uploading a gem file that has a crafted gem.homepage value in its .gemspec file. Affected versions
0.1.0
0.10.0
0.10.1
0.11.0
0.11.1
0.12.0
0.12.1
0.12.2
0.12.3
0.12.4
0.13.0
0.13.1
+ 34 more Show less
0.13.2
0.13.3
0.13.4
0.13.5
0.2.0
0.2.1
0.2.10
0.2.11
0.2.13
0.2.14
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.pre1
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.1pre1
0.7.0
0.8.0
0.9.0
Fixed in
0.13.6
References
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2017-14683
GHSA-qwv2-2x8g-g43g
May 13, 2022
Gem in a Box vulnerable to Cross-site Request Forgery
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
geminabox (aka Gem in a Box) before 0.13.7 has CSRF, as demonstrated by an unintended gem upload. Affected versions
0.1.0
0.10.0
0.10.1
0.11.0
0.11.1
0.12.0
0.12.1
0.12.2
0.12.3
0.12.4
0.13.0
0.13.1
+ 35 more Show less
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.2.0
0.2.1
0.2.10
0.2.11
0.2.13
0.2.14
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.pre1
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.1pre1
0.7.0
0.8.0
0.9.0
Fixed in
0.13.7
References
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2017-16792
GHSA-653m-r33x-39ff
Nov 29, 2017
Geminabox contains Cross-site Scripting
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Stored cross-site scripting (XSS) vulnerability in "geminabox" (Gem in a Box) before 0.13.10 allows attackers to inject arbitrary web script via the "homepage" value of a ".gemspec" file, related to views/gem.erb and views/index.erb. Affected versions
0.1.0
0.10.0
0.10.1
0.11.0
0.11.1
0.12.0
0.12.1
0.12.2
0.12.3
0.12.4
0.13.0
0.13.1
+ 38 more Show less
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.13.7
0.13.8
0.13.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.13
0.2.14
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.pre1
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.1pre1
0.7.0
0.8.0
0.9.0
Fixed in
0.13.10
References Updated Nov 08, 2023 · Source: OSV.dev | ||
0.10.0
minor
3 CVEs
CVE-2017-14506
GHSA-98hq-3qvg-pg78
May 13, 2022
Gem in a Box vulnerable to Cross-site Scripting
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
geminabox (aka Gem in a Box) before 0.13.6 is vulnerable to Cross-site Scripting (XSS), as demonstrated by uploading a gem file that has a crafted gem.homepage value in its .gemspec file. Affected versions
0.1.0
0.10.0
0.10.1
0.11.0
0.11.1
0.12.0
0.12.1
0.12.2
0.12.3
0.12.4
0.13.0
0.13.1
+ 34 more Show less
0.13.2
0.13.3
0.13.4
0.13.5
0.2.0
0.2.1
0.2.10
0.2.11
0.2.13
0.2.14
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.pre1
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.1pre1
0.7.0
0.8.0
0.9.0
Fixed in
0.13.6
References
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2017-14683
GHSA-qwv2-2x8g-g43g
May 13, 2022
Gem in a Box vulnerable to Cross-site Request Forgery
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
geminabox (aka Gem in a Box) before 0.13.7 has CSRF, as demonstrated by an unintended gem upload. Affected versions
0.1.0
0.10.0
0.10.1
0.11.0
0.11.1
0.12.0
0.12.1
0.12.2
0.12.3
0.12.4
0.13.0
0.13.1
+ 35 more Show less
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.2.0
0.2.1
0.2.10
0.2.11
0.2.13
0.2.14
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.pre1
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.1pre1
0.7.0
0.8.0
0.9.0
Fixed in
0.13.7
References
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2017-16792
GHSA-653m-r33x-39ff
Nov 29, 2017
Geminabox contains Cross-site Scripting
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Stored cross-site scripting (XSS) vulnerability in "geminabox" (Gem in a Box) before 0.13.10 allows attackers to inject arbitrary web script via the "homepage" value of a ".gemspec" file, related to views/gem.erb and views/index.erb. Affected versions
0.1.0
0.10.0
0.10.1
0.11.0
0.11.1
0.12.0
0.12.1
0.12.2
0.12.3
0.12.4
0.13.0
0.13.1
+ 38 more Show less
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.13.7
0.13.8
0.13.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.13
0.2.14
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.pre1
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.1pre1
0.7.0
0.8.0
0.9.0
Fixed in
0.13.10
References Updated Nov 08, 2023 · Source: OSV.dev | ||
0.9.0
minor
3 CVEs
CVE-2017-14506
GHSA-98hq-3qvg-pg78
May 13, 2022
Gem in a Box vulnerable to Cross-site Scripting
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
geminabox (aka Gem in a Box) before 0.13.6 is vulnerable to Cross-site Scripting (XSS), as demonstrated by uploading a gem file that has a crafted gem.homepage value in its .gemspec file. Affected versions
0.1.0
0.10.0
0.10.1
0.11.0
0.11.1
0.12.0
0.12.1
0.12.2
0.12.3
0.12.4
0.13.0
0.13.1
+ 34 more Show less
0.13.2
0.13.3
0.13.4
0.13.5
0.2.0
0.2.1
0.2.10
0.2.11
0.2.13
0.2.14
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.pre1
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.1pre1
0.7.0
0.8.0
0.9.0
Fixed in
0.13.6
References
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2017-14683
GHSA-qwv2-2x8g-g43g
May 13, 2022
Gem in a Box vulnerable to Cross-site Request Forgery
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
geminabox (aka Gem in a Box) before 0.13.7 has CSRF, as demonstrated by an unintended gem upload. Affected versions
0.1.0
0.10.0
0.10.1
0.11.0
0.11.1
0.12.0
0.12.1
0.12.2
0.12.3
0.12.4
0.13.0
0.13.1
+ 35 more Show less
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.2.0
0.2.1
0.2.10
0.2.11
0.2.13
0.2.14
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.pre1
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.1pre1
0.7.0
0.8.0
0.9.0
Fixed in
0.13.7
References
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2017-16792
GHSA-653m-r33x-39ff
Nov 29, 2017
Geminabox contains Cross-site Scripting
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Stored cross-site scripting (XSS) vulnerability in "geminabox" (Gem in a Box) before 0.13.10 allows attackers to inject arbitrary web script via the "homepage" value of a ".gemspec" file, related to views/gem.erb and views/index.erb. Affected versions
0.1.0
0.10.0
0.10.1
0.11.0
0.11.1
0.12.0
0.12.1
0.12.2
0.12.3
0.12.4
0.13.0
0.13.1
+ 38 more Show less
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.13.7
0.13.8
0.13.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.13
0.2.14
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.pre1
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.1pre1
0.7.0
0.8.0
0.9.0
Fixed in
0.13.10
References Updated Nov 08, 2023 · Source: OSV.dev | ||
0.8.0
minor
3 CVEs
CVE-2017-14506
GHSA-98hq-3qvg-pg78
May 13, 2022
Gem in a Box vulnerable to Cross-site Scripting
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
geminabox (aka Gem in a Box) before 0.13.6 is vulnerable to Cross-site Scripting (XSS), as demonstrated by uploading a gem file that has a crafted gem.homepage value in its .gemspec file. Affected versions
0.1.0
0.10.0
0.10.1
0.11.0
0.11.1
0.12.0
0.12.1
0.12.2
0.12.3
0.12.4
0.13.0
0.13.1
+ 34 more Show less
0.13.2
0.13.3
0.13.4
0.13.5
0.2.0
0.2.1
0.2.10
0.2.11
0.2.13
0.2.14
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.pre1
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.1pre1
0.7.0
0.8.0
0.9.0
Fixed in
0.13.6
References
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2017-14683
GHSA-qwv2-2x8g-g43g
May 13, 2022
Gem in a Box vulnerable to Cross-site Request Forgery
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
geminabox (aka Gem in a Box) before 0.13.7 has CSRF, as demonstrated by an unintended gem upload. Affected versions
0.1.0
0.10.0
0.10.1
0.11.0
0.11.1
0.12.0
0.12.1
0.12.2
0.12.3
0.12.4
0.13.0
0.13.1
+ 35 more Show less
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.2.0
0.2.1
0.2.10
0.2.11
0.2.13
0.2.14
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.pre1
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.1pre1
0.7.0
0.8.0
0.9.0
Fixed in
0.13.7
References
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2017-16792
GHSA-653m-r33x-39ff
Nov 29, 2017
Geminabox contains Cross-site Scripting
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Stored cross-site scripting (XSS) vulnerability in "geminabox" (Gem in a Box) before 0.13.10 allows attackers to inject arbitrary web script via the "homepage" value of a ".gemspec" file, related to views/gem.erb and views/index.erb. Affected versions
0.1.0
0.10.0
0.10.1
0.11.0
0.11.1
0.12.0
0.12.1
0.12.2
0.12.3
0.12.4
0.13.0
0.13.1
+ 38 more Show less
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.13.7
0.13.8
0.13.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.13
0.2.14
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.pre1
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.1pre1
0.7.0
0.8.0
0.9.0
Fixed in
0.13.10
References Updated Nov 08, 2023 · Source: OSV.dev | ||
0.7.0
minor
3 CVEs
CVE-2017-14506
GHSA-98hq-3qvg-pg78
May 13, 2022
Gem in a Box vulnerable to Cross-site Scripting
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
geminabox (aka Gem in a Box) before 0.13.6 is vulnerable to Cross-site Scripting (XSS), as demonstrated by uploading a gem file that has a crafted gem.homepage value in its .gemspec file. Affected versions
0.1.0
0.10.0
0.10.1
0.11.0
0.11.1
0.12.0
0.12.1
0.12.2
0.12.3
0.12.4
0.13.0
0.13.1
+ 34 more Show less
0.13.2
0.13.3
0.13.4
0.13.5
0.2.0
0.2.1
0.2.10
0.2.11
0.2.13
0.2.14
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.pre1
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.1pre1
0.7.0
0.8.0
0.9.0
Fixed in
0.13.6
References
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2017-14683
GHSA-qwv2-2x8g-g43g
May 13, 2022
Gem in a Box vulnerable to Cross-site Request Forgery
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
geminabox (aka Gem in a Box) before 0.13.7 has CSRF, as demonstrated by an unintended gem upload. Affected versions
0.1.0
0.10.0
0.10.1
0.11.0
0.11.1
0.12.0
0.12.1
0.12.2
0.12.3
0.12.4
0.13.0
0.13.1
+ 35 more Show less
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.2.0
0.2.1
0.2.10
0.2.11
0.2.13
0.2.14
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.pre1
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.1pre1
0.7.0
0.8.0
0.9.0
Fixed in
0.13.7
References
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2017-16792
GHSA-653m-r33x-39ff
Nov 29, 2017
Geminabox contains Cross-site Scripting
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Stored cross-site scripting (XSS) vulnerability in "geminabox" (Gem in a Box) before 0.13.10 allows attackers to inject arbitrary web script via the "homepage" value of a ".gemspec" file, related to views/gem.erb and views/index.erb. Affected versions
0.1.0
0.10.0
0.10.1
0.11.0
0.11.1
0.12.0
0.12.1
0.12.2
0.12.3
0.12.4
0.13.0
0.13.1
+ 38 more Show less
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.13.7
0.13.8
0.13.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.13
0.2.14
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.pre1
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.1pre1
0.7.0
0.8.0
0.9.0
Fixed in
0.13.10
References Updated Nov 08, 2023 · Source: OSV.dev | ||
0.6.1
patch
3 CVEs
CVE-2017-14506
GHSA-98hq-3qvg-pg78
May 13, 2022
Gem in a Box vulnerable to Cross-site Scripting
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
geminabox (aka Gem in a Box) before 0.13.6 is vulnerable to Cross-site Scripting (XSS), as demonstrated by uploading a gem file that has a crafted gem.homepage value in its .gemspec file. Affected versions
0.1.0
0.10.0
0.10.1
0.11.0
0.11.1
0.12.0
0.12.1
0.12.2
0.12.3
0.12.4
0.13.0
0.13.1
+ 34 more Show less
0.13.2
0.13.3
0.13.4
0.13.5
0.2.0
0.2.1
0.2.10
0.2.11
0.2.13
0.2.14
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.pre1
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.1pre1
0.7.0
0.8.0
0.9.0
Fixed in
0.13.6
References
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2017-14683
GHSA-qwv2-2x8g-g43g
May 13, 2022
Gem in a Box vulnerable to Cross-site Request Forgery
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
geminabox (aka Gem in a Box) before 0.13.7 has CSRF, as demonstrated by an unintended gem upload. Affected versions
0.1.0
0.10.0
0.10.1
0.11.0
0.11.1
0.12.0
0.12.1
0.12.2
0.12.3
0.12.4
0.13.0
0.13.1
+ 35 more Show less
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.2.0
0.2.1
0.2.10
0.2.11
0.2.13
0.2.14
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.pre1
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.1pre1
0.7.0
0.8.0
0.9.0
Fixed in
0.13.7
References
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2017-16792
GHSA-653m-r33x-39ff
Nov 29, 2017
Geminabox contains Cross-site Scripting
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Stored cross-site scripting (XSS) vulnerability in "geminabox" (Gem in a Box) before 0.13.10 allows attackers to inject arbitrary web script via the "homepage" value of a ".gemspec" file, related to views/gem.erb and views/index.erb. Affected versions
0.1.0
0.10.0
0.10.1
0.11.0
0.11.1
0.12.0
0.12.1
0.12.2
0.12.3
0.12.4
0.13.0
0.13.1
+ 38 more Show less
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.13.7
0.13.8
0.13.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.13
0.2.14
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.pre1
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.1pre1
0.7.0
0.8.0
0.9.0
Fixed in
0.13.10
References Updated Nov 08, 2023 · Source: OSV.dev | ||
0.6.1pre1
pre
3 CVEs
CVE-2017-14506
GHSA-98hq-3qvg-pg78
May 13, 2022
Gem in a Box vulnerable to Cross-site Scripting
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
geminabox (aka Gem in a Box) before 0.13.6 is vulnerable to Cross-site Scripting (XSS), as demonstrated by uploading a gem file that has a crafted gem.homepage value in its .gemspec file. Affected versions
0.1.0
0.10.0
0.10.1
0.11.0
0.11.1
0.12.0
0.12.1
0.12.2
0.12.3
0.12.4
0.13.0
0.13.1
+ 34 more Show less
0.13.2
0.13.3
0.13.4
0.13.5
0.2.0
0.2.1
0.2.10
0.2.11
0.2.13
0.2.14
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.pre1
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.1pre1
0.7.0
0.8.0
0.9.0
Fixed in
0.13.6
References
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2017-14683
GHSA-qwv2-2x8g-g43g
May 13, 2022
Gem in a Box vulnerable to Cross-site Request Forgery
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
geminabox (aka Gem in a Box) before 0.13.7 has CSRF, as demonstrated by an unintended gem upload. Affected versions
0.1.0
0.10.0
0.10.1
0.11.0
0.11.1
0.12.0
0.12.1
0.12.2
0.12.3
0.12.4
0.13.0
0.13.1
+ 35 more Show less
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.2.0
0.2.1
0.2.10
0.2.11
0.2.13
0.2.14
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.pre1
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.1pre1
0.7.0
0.8.0
0.9.0
Fixed in
0.13.7
References
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2017-16792
GHSA-653m-r33x-39ff
Nov 29, 2017
Geminabox contains Cross-site Scripting
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Stored cross-site scripting (XSS) vulnerability in "geminabox" (Gem in a Box) before 0.13.10 allows attackers to inject arbitrary web script via the "homepage" value of a ".gemspec" file, related to views/gem.erb and views/index.erb. Affected versions
0.1.0
0.10.0
0.10.1
0.11.0
0.11.1
0.12.0
0.12.1
0.12.2
0.12.3
0.12.4
0.13.0
0.13.1
+ 38 more Show less
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.13.7
0.13.8
0.13.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.13
0.2.14
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.pre1
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.1pre1
0.7.0
0.8.0
0.9.0
Fixed in
0.13.10
References Updated Nov 08, 2023 · Source: OSV.dev | ||
0.6.0
minor
3 CVEs
CVE-2017-14506
GHSA-98hq-3qvg-pg78
May 13, 2022
Gem in a Box vulnerable to Cross-site Scripting
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
geminabox (aka Gem in a Box) before 0.13.6 is vulnerable to Cross-site Scripting (XSS), as demonstrated by uploading a gem file that has a crafted gem.homepage value in its .gemspec file. Affected versions
0.1.0
0.10.0
0.10.1
0.11.0
0.11.1
0.12.0
0.12.1
0.12.2
0.12.3
0.12.4
0.13.0
0.13.1
+ 34 more Show less
0.13.2
0.13.3
0.13.4
0.13.5
0.2.0
0.2.1
0.2.10
0.2.11
0.2.13
0.2.14
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.pre1
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.1pre1
0.7.0
0.8.0
0.9.0
Fixed in
0.13.6
References
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2017-14683
GHSA-qwv2-2x8g-g43g
May 13, 2022
Gem in a Box vulnerable to Cross-site Request Forgery
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
geminabox (aka Gem in a Box) before 0.13.7 has CSRF, as demonstrated by an unintended gem upload. Affected versions
0.1.0
0.10.0
0.10.1
0.11.0
0.11.1
0.12.0
0.12.1
0.12.2
0.12.3
0.12.4
0.13.0
0.13.1
+ 35 more Show less
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.2.0
0.2.1
0.2.10
0.2.11
0.2.13
0.2.14
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.pre1
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.1pre1
0.7.0
0.8.0
0.9.0
Fixed in
0.13.7
References
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2017-16792
GHSA-653m-r33x-39ff
Nov 29, 2017
Geminabox contains Cross-site Scripting
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Stored cross-site scripting (XSS) vulnerability in "geminabox" (Gem in a Box) before 0.13.10 allows attackers to inject arbitrary web script via the "homepage" value of a ".gemspec" file, related to views/gem.erb and views/index.erb. Affected versions
0.1.0
0.10.0
0.10.1
0.11.0
0.11.1
0.12.0
0.12.1
0.12.2
0.12.3
0.12.4
0.13.0
0.13.1
+ 38 more Show less
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.13.7
0.13.8
0.13.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.13
0.2.14
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.pre1
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.1pre1
0.7.0
0.8.0
0.9.0
Fixed in
0.13.10
References Updated Nov 08, 2023 · Source: OSV.dev |