Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-5mgj-mvv8-46mw

Опубликовано: 17 мая 2022
Источник: github
Github: Прошло ревью

Описание

RubyGems does not verify SSL certificate

RubyGems before 1.8.23 does not verify an SSL certificate, which allows remote attackers to modify a gem during installation via a man-in-the-middle attack.

Пакеты

Наименование

rubygems-update

rubygems
Затронутые версииВерсия исправления

< 1.8.23

1.8.23

EPSS

Процентиль: 50%
0.00272
Низкий

Связанные уязвимости

ubuntu
больше 11 лет назад

RubyGems before 1.8.23 does not verify an SSL certificate, which allows remote attackers to modify a gem during installation via a man-in-the-middle attack.

redhat
около 13 лет назад

RubyGems before 1.8.23 does not verify an SSL certificate, which allows remote attackers to modify a gem during installation via a man-in-the-middle attack.

nvd
больше 11 лет назад

RubyGems before 1.8.23 does not verify an SSL certificate, which allows remote attackers to modify a gem during installation via a man-in-the-middle attack.

debian
больше 11 лет назад

RubyGems before 1.8.23 does not verify an SSL certificate, which allow ...

oracle-oval
больше 11 лет назад

ELSA-2013-1441: rubygems security update (MODERATE)

EPSS

Процентиль: 50%
0.00272
Низкий