CVE Vulnerabilities

CVE-2012-2125

Published: Oct 01, 2013 | Modified: Jan 14, 2014
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:N
RedHat/V2
4 MODERATE
AV:N/AC:H/Au:N/C:P/I:P/A:N
RedHat/V3
Ubuntu
LOW

RubyGems before 1.8.23 can redirect HTTPS connections to HTTP, which makes it easier for remote attackers to observe or modify a gem during installation via a man-in-the-middle attack.

Affected Software

Name Vendor Start Version End Version
Rubygems Rubygems * 1.8.22 (including)
Rubygems Rubygems 1.8.0 (including) 1.8.0 (including)
Rubygems Rubygems 1.8.1 (including) 1.8.1 (including)
Rubygems Rubygems 1.8.2 (including) 1.8.2 (including)
Rubygems Rubygems 1.8.3 (including) 1.8.3 (including)
Rubygems Rubygems 1.8.4 (including) 1.8.4 (including)
Rubygems Rubygems 1.8.5 (including) 1.8.5 (including)
Rubygems Rubygems 1.8.6 (including) 1.8.6 (including)
Rubygems Rubygems 1.8.7 (including) 1.8.7 (including)
Rubygems Rubygems 1.8.8 (including) 1.8.8 (including)
Rubygems Rubygems 1.8.9 (including) 1.8.9 (including)
Rubygems Rubygems 1.8.10 (including) 1.8.10 (including)
Rubygems Rubygems 1.8.11 (including) 1.8.11 (including)
Rubygems Rubygems 1.8.12 (including) 1.8.12 (including)
Rubygems Rubygems 1.8.13 (including) 1.8.13 (including)
Rubygems Rubygems 1.8.14 (including) 1.8.14 (including)
Rubygems Rubygems 1.8.15 (including) 1.8.15 (including)
Rubygems Rubygems 1.8.16 (including) 1.8.16 (including)
Rubygems Rubygems 1.8.17 (including) 1.8.17 (including)
Rubygems Rubygems 1.8.18 (including) 1.8.18 (including)
Rubygems Rubygems 1.8.19 (including) 1.8.19 (including)
Rubygems Rubygems 1.8.20 (including) 1.8.20 (including)
Rubygems Rubygems 1.8.21 (including) 1.8.21 (including)
Red Hat Enterprise Linux 6 RedHat rubygems-0:1.3.7-4.el6_4 *
Red Hat Enterprise MRG 2 RedHat cumin-0:0.1.5787-4.el6 *
Red Hat Enterprise MRG 2 RedHat rubygems-0:1.8.23.2-1.el6 *
RHEL 6 Version of OpenShift Enterprise 1.2 RedHat rubygems-0:1.8.24-4.el6op *
Jruby Ubuntu artful *
Jruby Ubuntu esm-infra-legacy/trusty *
Jruby Ubuntu lucid *
Jruby Ubuntu natty *
Jruby Ubuntu oneiric *
Jruby Ubuntu precise *
Jruby Ubuntu quantal *
Jruby Ubuntu raring *
Jruby Ubuntu saucy *
Jruby Ubuntu trusty *
Jruby Ubuntu trusty/esm *
Jruby Ubuntu utopic *
Jruby Ubuntu vivid *
Jruby Ubuntu wily *
Jruby Ubuntu yakkety *
Jruby Ubuntu zesty *
Ruby1.9.1 Ubuntu lucid *
Ruby1.9.1 Ubuntu natty *
Ruby1.9.1 Ubuntu oneiric *
Ruby1.9.1 Ubuntu precise *
Ruby1.9.1 Ubuntu upstream *
Rubygems Ubuntu oneiric *
Rubygems Ubuntu precise *
Rubygems Ubuntu upstream *

References