CVE-2024-21654 - CVE House
Back to Database
Status published Medium CVE-2024-21654

rubygems.org MFA Bypass through password reset function could allow account takeover

Vulnerability Description

Rubygems.org is the Ruby community's gem hosting service. Rubygems.org users with MFA enabled would normally be protected from account takeover in the case of email account takeover. However, a workaround on the forgotten password form allows an attacker to bypass the MFA requirement and takeover the account. This vulnerability has been patched in commit 0b3272a.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-21654

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

rubygems.org
Vulnerable Versions:
< commit 0b3272a

Timeline

Official Publish: January 12th, 2024
Last Modified: October 24th, 2024
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N

Weaknesses (CWE)