Lucene search

K
githubGitHub Advisory DatabaseGHSA-5MGJ-MVV8-46MW
HistoryMay 17, 2022 - 4:54 a.m.

RubyGems does not verify SSL certificate

2022-05-1704:54:47
GitHub Advisory Database
github.com
14
rubygems
ssl certificate
vulnerability
attack
installation
software

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

EPSS

0.003

Percentile

69.6%

RubyGems before 1.8.23 does not verify an SSL certificate, which allows remote attackers to modify a gem during installation via a man-in-the-middle attack.

Affected configurations

Vulners
Node
rubygemsrubygems-updateRange<1.8.23
VendorProductVersionCPE
rubygemsrubygems-update*cpe:2.3:a:rubygems:rubygems-update:*:*:*:*:*:*:*:*

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

EPSS

0.003

Percentile

69.6%