Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-wp3j-rvfp-624h

Опубликовано: 14 мая 2022
Источник: github
Github: Прошло ревью

Описание

RubyGems vulnerable to DNS hijack attack

RubyGems 2.0.x before 2.0.16, 2.2.x before 2.2.4, and 2.4.x before 2.4.7 does not validate the hostname when fetching gems or making API requests, which allows remote attackers to redirect requests to arbitrary domains via a crafted DNS SRV record, aka a "DNS hijack attack."

Пакеты

Наименование

rubygems-update

rubygems
Затронутые версииВерсия исправления

>= 2.0.0, < 2.0.16

2.0.16

Наименование

rubygems-update

rubygems
Затронутые версииВерсия исправления

>= 2.2.0, < 2.2.4

2.2.4

Наименование

rubygems-update

rubygems
Затронутые версииВерсия исправления

>= 2.4.0, < 2.4.7

2.4.7

EPSS

Процентиль: 85%
0.02401
Низкий

Дефекты

CWE-350

Связанные уязвимости

ubuntu
больше 10 лет назад

RubyGems 2.0.x before 2.0.16, 2.2.x before 2.2.4, and 2.4.x before 2.4.7 does not validate the hostname when fetching gems or making API requests, which allows remote attackers to redirect requests to arbitrary domains via a crafted DNS SRV record, aka a "DNS hijack attack."

redhat
больше 10 лет назад

RubyGems 2.0.x before 2.0.16, 2.2.x before 2.2.4, and 2.4.x before 2.4.7 does not validate the hostname when fetching gems or making API requests, which allows remote attackers to redirect requests to arbitrary domains via a crafted DNS SRV record, aka a "DNS hijack attack."

nvd
больше 10 лет назад

RubyGems 2.0.x before 2.0.16, 2.2.x before 2.2.4, and 2.4.x before 2.4.7 does not validate the hostname when fetching gems or making API requests, which allows remote attackers to redirect requests to arbitrary domains via a crafted DNS SRV record, aka a "DNS hijack attack."

debian
больше 10 лет назад

RubyGems 2.0.x before 2.0.16, 2.2.x before 2.2.4, and 2.4.x before 2.4 ...

suse-cvrf
почти 9 лет назад

Security update for ruby2.1

EPSS

Процентиль: 85%
0.02401
Низкий

Дефекты

CWE-350