SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2024-21654

However, a workaround on the forgotten password form allows an attacker to bypass the MFA requirement and takeover the account.

CRITICAL 9.8EPSS 0.48%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (0.48%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

Rubygems.org is the Ruby community's gem hosting service. Rubygems.org users with MFA enabled would normally be protected from account takeover in the case of email account takeover. However, a workaround on the forgotten password form allows an attacker to bypass the MFA requirement and takeover the account. This vulnerability has been patched in commit 0b3272a.

CVSS 3.1
9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
0.48% probability · 40th percentile
CISA KEV
Not listed
Weakness
CWE-287, CWE-306
Affected
rubygems/rubygems.org
Source
security-advisories@github.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.