Skip to content

Ability to create users with arbitrary unverified emails

High
segiddins published GHSA-8qpf-wf2p-25vg Sep 1, 2022

Package

bundler rubygems.org (RubyGems)

Affected versions

n/a

Patched versions

n/a

Description

Summary

A bug in password & email change confirmation code allowed an attacker to change their RubyGems.org account's email to an unowned email address.

Impact

Having access to an account whose email has been changed could enable an attacker to save API keys for that account, and when a legitimate user attempts to create an account with their email (and has to reset password to gain access) and is granted access to other gems, the attacker would then be able to publish & yank versions of those gems.

Patches

The bug was fixed via 90c9e6a

Severity

High

CVE ID

CVE-2022-36073

Weaknesses

No CWEs

Credits