CVE Vulnerabilities

CVE-2012-2126

Published: Oct 01, 2013 | Modified: Jan 14, 2014
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N
RedHat/V2
4 MODERATE
AV:N/AC:H/Au:N/C:P/I:P/A:N
RedHat/V3
Ubuntu
MEDIUM

RubyGems before 1.8.23 does not verify an SSL certificate, which allows remote attackers to modify a gem during installation via a man-in-the-middle attack.

Affected Software

Name Vendor Start Version End Version
Rubygems Rubygems * 1.8.22 (including)
Rubygems Rubygems 1.8.0 (including) 1.8.0 (including)
Rubygems Rubygems 1.8.1 (including) 1.8.1 (including)
Rubygems Rubygems 1.8.2 (including) 1.8.2 (including)
Rubygems Rubygems 1.8.3 (including) 1.8.3 (including)
Rubygems Rubygems 1.8.4 (including) 1.8.4 (including)
Rubygems Rubygems 1.8.5 (including) 1.8.5 (including)
Rubygems Rubygems 1.8.6 (including) 1.8.6 (including)
Rubygems Rubygems 1.8.7 (including) 1.8.7 (including)
Rubygems Rubygems 1.8.8 (including) 1.8.8 (including)
Rubygems Rubygems 1.8.9 (including) 1.8.9 (including)
Rubygems Rubygems 1.8.10 (including) 1.8.10 (including)
Rubygems Rubygems 1.8.11 (including) 1.8.11 (including)
Rubygems Rubygems 1.8.12 (including) 1.8.12 (including)
Rubygems Rubygems 1.8.13 (including) 1.8.13 (including)
Rubygems Rubygems 1.8.14 (including) 1.8.14 (including)
Rubygems Rubygems 1.8.15 (including) 1.8.15 (including)
Rubygems Rubygems 1.8.16 (including) 1.8.16 (including)
Rubygems Rubygems 1.8.17 (including) 1.8.17 (including)
Rubygems Rubygems 1.8.18 (including) 1.8.18 (including)
Rubygems Rubygems 1.8.19 (including) 1.8.19 (including)
Rubygems Rubygems 1.8.20 (including) 1.8.20 (including)
Rubygems Rubygems 1.8.21 (including) 1.8.21 (including)
Red Hat Enterprise Linux 6 RedHat rubygems-0:1.3.7-4.el6_4 *
Red Hat Enterprise MRG 2 RedHat cumin-0:0.1.5787-4.el6 *
Red Hat Enterprise MRG 2 RedHat rubygems-0:1.8.23.2-1.el6 *
RHEL 6 Version of OpenShift Enterprise 1.2 RedHat rubygems-0:1.8.24-4.el6op *
Jruby Ubuntu artful *
Jruby Ubuntu cosmic *
Jruby Ubuntu disco *
Jruby Ubuntu esm-infra-legacy/trusty *
Jruby Ubuntu lucid *
Jruby Ubuntu natty *
Jruby Ubuntu oneiric *
Jruby Ubuntu precise *
Jruby Ubuntu quantal *
Jruby Ubuntu raring *
Jruby Ubuntu saucy *
Jruby Ubuntu trusty *
Jruby Ubuntu trusty/esm *
Jruby Ubuntu utopic *
Jruby Ubuntu vivid *
Jruby Ubuntu wily *
Jruby Ubuntu yakkety *
Jruby Ubuntu zesty *
Ruby1.9.1 Ubuntu lucid *
Ruby1.9.1 Ubuntu natty *
Ruby1.9.1 Ubuntu oneiric *
Ruby1.9.1 Ubuntu precise *
Ruby1.9.1 Ubuntu upstream *
Rubygems Ubuntu oneiric *
Rubygems Ubuntu precise *
Rubygems Ubuntu upstream *

References