TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Multiple vulnerabilities in RubyGems

189 点作者 omarish超过 7 年前

6 条评论

travjones超过 7 年前
&gt;&gt; &quot;a vulnerability in the gem installer that allowed a malicious gem to overwrite arbitrary files&quot;<p>Yeeks. Not good.<p>(sudo) gem update --system ASAP
评论 #15130283 未加载
评论 #15130173 未加载
评论 #15128898 未加载
评论 #15128817 未加载
trapperkeeper74超过 7 年前
I have a mirror of all Rubygems from last month. Should I scan em for PoCs?
评论 #15132111 未加载
评论 #15132128 未加载
评论 #15132467 未加载
jzelinskie超过 7 年前
Is the work on adding TUF to RubyGems still happening? I can only find this stagnant PR: <a href="https:&#x2F;&#x2F;github.com&#x2F;rubygems&#x2F;rubygems&#x2F;pull&#x2F;719" rel="nofollow">https:&#x2F;&#x2F;github.com&#x2F;rubygems&#x2F;rubygems&#x2F;pull&#x2F;719</a>
评论 #15130648 未加载
kichik超过 7 年前
Is there a more detailed description of the vulnerabilities somewhere?
评论 #15128778 未加载
baron816超过 7 年前
I&#x27;m sure this has been brought up before, but I think HN should have a special tab where submissions like this get pinned--Important stores where people need to take action on stuff concerning security holes or political events (e.g. Net neutrality).
评论 #15131070 未加载
评论 #15130099 未加载
评论 #15130207 未加载
评论 #15130999 未加载
LunaSea超过 7 年前
Ruby, the gift that keeps on giving.