Lucene search

K
nvd[email protected]NVD:CVE-2012-2125
HistoryOct 01, 2013 - 5:55 p.m.

CVE-2012-2125

2013-10-0117:55:03
web.nvd.nist.gov
6

CVSS2

5.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:P/A:N

AI Score

6.2

Confidence

Low

EPSS

0.004

Percentile

74.0%

RubyGems before 1.8.23 can redirect HTTPS connections to HTTP, which makes it easier for remote attackers to observe or modify a gem during installation via a man-in-the-middle attack.

Affected configurations

Nvd
Node
rubygemsrubygemsRange1.8.22
OR
rubygemsrubygemsMatch1.8.0
OR
rubygemsrubygemsMatch1.8.1
OR
rubygemsrubygemsMatch1.8.2
OR
rubygemsrubygemsMatch1.8.3
OR
rubygemsrubygemsMatch1.8.4
OR
rubygemsrubygemsMatch1.8.5
OR
rubygemsrubygemsMatch1.8.6
OR
rubygemsrubygemsMatch1.8.7
OR
rubygemsrubygemsMatch1.8.8
OR
rubygemsrubygemsMatch1.8.9
OR
rubygemsrubygemsMatch1.8.10
OR
rubygemsrubygemsMatch1.8.11
OR
rubygemsrubygemsMatch1.8.12
OR
rubygemsrubygemsMatch1.8.13
OR
rubygemsrubygemsMatch1.8.14
OR
rubygemsrubygemsMatch1.8.15
OR
rubygemsrubygemsMatch1.8.16
OR
rubygemsrubygemsMatch1.8.17
OR
rubygemsrubygemsMatch1.8.18
OR
rubygemsrubygemsMatch1.8.19
OR
rubygemsrubygemsMatch1.8.20
OR
rubygemsrubygemsMatch1.8.21
AND
redhatopenshiftMatch1.2.2-enterprise
OR
canonicalubuntu_linuxMatch12.04-lts
VendorProductVersionCPE
rubygemsrubygems*cpe:2.3:a:rubygems:rubygems:*:*:*:*:*:*:*:*
rubygemsrubygems1.8.0cpe:2.3:a:rubygems:rubygems:1.8.0:*:*:*:*:*:*:*
rubygemsrubygems1.8.1cpe:2.3:a:rubygems:rubygems:1.8.1:*:*:*:*:*:*:*
rubygemsrubygems1.8.2cpe:2.3:a:rubygems:rubygems:1.8.2:*:*:*:*:*:*:*
rubygemsrubygems1.8.3cpe:2.3:a:rubygems:rubygems:1.8.3:*:*:*:*:*:*:*
rubygemsrubygems1.8.4cpe:2.3:a:rubygems:rubygems:1.8.4:*:*:*:*:*:*:*
rubygemsrubygems1.8.5cpe:2.3:a:rubygems:rubygems:1.8.5:*:*:*:*:*:*:*
rubygemsrubygems1.8.6cpe:2.3:a:rubygems:rubygems:1.8.6:*:*:*:*:*:*:*
rubygemsrubygems1.8.7cpe:2.3:a:rubygems:rubygems:1.8.7:*:*:*:*:*:*:*
rubygemsrubygems1.8.8cpe:2.3:a:rubygems:rubygems:1.8.8:*:*:*:*:*:*:*
Rows per page:
1-10 of 251

CVSS2

5.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:P/A:N

AI Score

6.2

Confidence

Low

EPSS

0.004

Percentile

74.0%