{"id":"CVE-2024-21654","summary":"rubygems.org MFA Bypass through password reset function could allow account takeover ","details":"Rubygems.org is the Ruby community's gem hosting service. Rubygems.org users with MFA enabled would normally be protected from account takeover in the case of email account takeover. However, a workaround on the forgotten password form allows an attacker to bypass the MFA requirement and takeover the account. This vulnerability has been patched in commit 0b3272a.","aliases":["GHSA-4v23-vj8h-7jp2"],"modified":"2026-09-16T03:30:54.015631216Z","published":"2024-01-12T20:59:43.094Z","database_specific":{"cwe_ids":["CWE-287"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/21xxx/CVE-2024-21654.json","unresolved_ranges":[{"source":"AFFECTED_FIELD","extracted_events":[{"fixed":"commit0b3272a"}]}],"cna_assigner":"GitHub_M"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/21xxx/CVE-2024-21654.json"},{"type":"ADVISORY","url":"https://github.com/rubygems/rubygems.org/security/advisories/GHSA-4v23-vj8h-7jp2"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-21654"},{"type":"FIX","url":"https://github.com/rubygems/rubygems.org/commit/0b3272ac17b45748ee0d1867c49867c7deb26565"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/rubygems/rubygems.org","events":[{"introduced":"0"},{"fixed":"0b3272ac17b45748ee0d1867c49867c7deb26565"}],"database_specific":{"source":"REFERENCES"}}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-21654.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N"}]}