Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-73w7-6w9g-gc8w

Опубликовано: 13 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 8.1

Описание

RubyGems has Origin Validation Error vulnerability

RubyGems version 2.6.12 and earlier is vulnerable to a DNS hijacking vulnerability that allows a MITM attacker to force the RubyGems client to download and install gems from a server that the attacker controls.

Пакеты

Наименование

rubygems-update

rubygems
Затронутые версииВерсия исправления

< 2.6.13

2.6.13

EPSS

Процентиль: 87%
0.03392
Низкий

8.1 High

CVSS3

Дефекты

CWE-346
CWE-350

Связанные уязвимости

CVSS3: 8.1
ubuntu
около 8 лет назад

RubyGems version 2.6.12 and earlier is vulnerable to a DNS hijacking vulnerability that allows a MITM attacker to force the RubyGems client to download and install gems from a server that the attacker controls.

CVSS3: 7.5
redhat
около 8 лет назад

RubyGems version 2.6.12 and earlier is vulnerable to a DNS hijacking vulnerability that allows a MITM attacker to force the RubyGems client to download and install gems from a server that the attacker controls.

CVSS3: 8.1
nvd
около 8 лет назад

RubyGems version 2.6.12 and earlier is vulnerable to a DNS hijacking vulnerability that allows a MITM attacker to force the RubyGems client to download and install gems from a server that the attacker controls.

CVSS3: 8.1
debian
около 8 лет назад

RubyGems version 2.6.12 and earlier is vulnerable to a DNS hijacking v ...

oracle-oval
больше 7 лет назад

ELSA-2018-0378: ruby security update (IMPORTANT)

EPSS

Процентиль: 87%
0.03392
Низкий

8.1 High

CVSS3

Дефекты

CWE-346
CWE-350