Description of problem: gem update seems to work. We should disable gem updates from rubygems.org. See gem sources -l
I am not sure this is CloudForms issue. Gem is a system-wide tool, do not confuse this with Bundler (Gemfiles, Gemfiles.lock). I don't see the point "disabling gem updates" system-wide, whatever it means. Bundle update uses our own gem repo, but it's not recommended using it. We could only remove the source "fedorahoste.org/repos/katello" line maybe, but I don't see much added value. Not a bug?
I agree with Lukas, while 'gem update' could really screw up your CloudForms install there isn't a whole lot we can do to block this except for overriding the functionality contained within the rubygems package itself. Since we rely on rubygems to resolve dependencies for our ruby packages I don't think we want to forcibly override the behaviour in this upstream package. Going to close as WONTFIX but if you feel we really need to address this please re-open and we can raise the issue with a larger group.