Lucene search

K
osvGoogleOSV:GHSA-5MGJ-MVV8-46MW
HistoryMay 17, 2022 - 4:54 a.m.

RubyGems does not verify SSL certificate

2022-05-1704:54:47
Google
osv.dev
17
rubygems
ssl certificate
vulnerability
remote attackers
gem modification

EPSS

0.003

Percentile

69.6%

RubyGems before 1.8.23 does not verify an SSL certificate, which allows remote attackers to modify a gem during installation via a man-in-the-middle attack.