Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-228f-g3h7-3fj3

Опубликовано: 17 мая 2022
Источник: github
Github: Прошло ревью

Описание

RubyGems HTTPS to HTTP redirect

RubyGems before 1.8.23 can redirect HTTPS connections to HTTP, which makes it easier for remote attackers to observe or modify a gem during installation via a man-in-the-middle attack.

Пакеты

Наименование

rubygems-update

rubygems
Затронутые версииВерсия исправления

< 1.8.23

1.8.23

EPSS

Процентиль: 69%
0.00638
Низкий

Связанные уязвимости

ubuntu
больше 11 лет назад

RubyGems before 1.8.23 can redirect HTTPS connections to HTTP, which makes it easier for remote attackers to observe or modify a gem during installation via a man-in-the-middle attack.

redhat
около 13 лет назад

RubyGems before 1.8.23 can redirect HTTPS connections to HTTP, which makes it easier for remote attackers to observe or modify a gem during installation via a man-in-the-middle attack.

nvd
больше 11 лет назад

RubyGems before 1.8.23 can redirect HTTPS connections to HTTP, which makes it easier for remote attackers to observe or modify a gem during installation via a man-in-the-middle attack.

debian
больше 11 лет назад

RubyGems before 1.8.23 can redirect HTTPS connections to HTTP, which m ...

oracle-oval
больше 11 лет назад

ELSA-2013-1441: rubygems security update (MODERATE)

EPSS

Процентиль: 69%
0.00638
Низкий