CVE

Id
94774  
CVE No.
CVE-2016-7954  
Status
Candidate  
Description
Bundler 1.x might allow remote attackers to inject arbitrary Ruby code into an application by leveraging a gem name collision on a secondary source. NOTE: this might overlap CVE-2013-0334.  
Phase
Assigned (20160909)  
Votes
None (candidate not yet proposed)  
Comments