2017-09-25 08:00:00
mitre
PUBLISHED
geminabox (aka Gem in a Box) before 0.13.7 has CSRF, as demonstrated by an unintended gem upload.