Disclosure summary
Bundler 1.16.0 through 2.2.9 and 2.2.11 through 2.2.16 sometimes chooses a dependency source based on the highest gem version number, which means that a rogue gem found at a public source may be chosen, even if the intended choice was a private gem that is a dependency of another private gem that is explicitly depended on by the application. NOTE: it is not correct to use CVE-2021-24105 for every "Dependency Confusion" issue in every product.
Source-reported weakness categories
NVD-CWE-noinfo
Source-specific records & product guidance
Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.
NIST National Vulnerability Database · NVD-CVE-2020-36327
Open original source · Updated Oct 08, 2026
Only CPE matches marked vulnerable=true are indexed. AND/OR platform conditions must be checked in the original NVD record.
| Vendor | Product / association | Version / bounds |
|---|---|---|
| bundler | bundler | * {"versionStartIncluding":"2.2.11","versionEndIncluding":"2.2.16"} |
| fedoraproject | fedora | 34 |
| microsoft | package_manager_configurations | - |
Original records & references
- NIST NVD record
- CVE Program record
- bundler.io — Vendor Advisory
- github.com — Exploit, Issue Tracking, Third Party Advisory
- lists.fedoraproject.org
- mensfeld.pl — Third Party Advisory
- msrc.microsoft.com — Patch, Vendor Advisory
- www.zofrex.com — Exploit, Third Party Advisory
- bundler.io — Vendor Advisory
- github.com — Exploit, Issue Tracking, Third Party Advisory
- lists.fedoraproject.org
- mensfeld.pl — Third Party Advisory
- msrc.microsoft.com — Patch, Vendor Advisory
- www.zofrex.com — Exploit, Third Party Advisory
PUBLISHED 2021-04-28T23:15:08-04:00
MODIFIED 2026-10-08T17:17:30-04:00
INGESTED 2026-10-10T20:50:20-04:00