CVE Vulnerabilities

CVE-2012-2125

Published: Oct 01, 2013 | Modified: Apr 11, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:N
RedHat/V2
4 MODERATE
AV:N/AC:H/Au:N/C:P/I:P/A:N
RedHat/V3
Ubuntu
LOW
root.io logo minimus.io logo echo.ai logo

RubyGems before 1.8.23 can redirect HTTPS connections to HTTP, which makes it easier for remote attackers to observe or modify a gem during installation via a man-in-the-middle attack.

Affected Software

NameVendorStart VersionEnd Version
RubygemsRubygems*1.8.22 (including)
RubygemsRubygems1.8.0 (including)1.8.0 (including)
RubygemsRubygems1.8.1 (including)1.8.1 (including)
RubygemsRubygems1.8.2 (including)1.8.2 (including)
RubygemsRubygems1.8.3 (including)1.8.3 (including)
RubygemsRubygems1.8.4 (including)1.8.4 (including)
RubygemsRubygems1.8.5 (including)1.8.5 (including)
RubygemsRubygems1.8.6 (including)1.8.6 (including)
RubygemsRubygems1.8.7 (including)1.8.7 (including)
RubygemsRubygems1.8.8 (including)1.8.8 (including)
RubygemsRubygems1.8.9 (including)1.8.9 (including)
RubygemsRubygems1.8.10 (including)1.8.10 (including)
RubygemsRubygems1.8.11 (including)1.8.11 (including)
RubygemsRubygems1.8.12 (including)1.8.12 (including)
RubygemsRubygems1.8.13 (including)1.8.13 (including)
RubygemsRubygems1.8.14 (including)1.8.14 (including)
RubygemsRubygems1.8.15 (including)1.8.15 (including)
RubygemsRubygems1.8.16 (including)1.8.16 (including)
RubygemsRubygems1.8.17 (including)1.8.17 (including)
RubygemsRubygems1.8.18 (including)1.8.18 (including)
RubygemsRubygems1.8.19 (including)1.8.19 (including)
RubygemsRubygems1.8.20 (including)1.8.20 (including)
RubygemsRubygems1.8.21 (including)1.8.21 (including)
Red Hat Enterprise Linux 6RedHatrubygems-0:1.3.7-4.el6_4*
Red Hat Enterprise MRG 2RedHatcumin-0:0.1.5787-4.el6*
Red Hat Enterprise MRG 2RedHatrubygems-0:1.8.23.2-1.el6*
RHEL 6 Version of OpenShift Enterprise 1.2RedHatrubygems-0:1.8.24-4.el6op*
JrubyUbuntuartful*
JrubyUbuntuesm-infra-legacy/trusty*
JrubyUbuntulucid*
JrubyUbuntunatty*
JrubyUbuntuoneiric*
JrubyUbuntuprecise*
JrubyUbuntuquantal*
JrubyUbunturaring*
JrubyUbuntusaucy*
JrubyUbuntutrusty*
JrubyUbuntutrusty/esm*
JrubyUbuntuutopic*
JrubyUbuntuvivid*
JrubyUbuntuwily*
JrubyUbuntuyakkety*
JrubyUbuntuzesty*
Ruby1.9.1Ubuntulucid*
Ruby1.9.1Ubuntunatty*
Ruby1.9.1Ubuntuoneiric*
Ruby1.9.1Ubuntuprecise*
Ruby1.9.1Ubuntuupstream*
RubygemsUbuntuoneiric*
RubygemsUbuntuprecise*
RubygemsUbuntuupstream*

References