Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:18924
HistoryMay 16, 2019 - 2:16 a.m.

Improper Access Control

2019-05-1602:16:34
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
5

0.008 Low

EPSS

Percentile

81.1%

RubyGems is vulnerable to improper access control. A remote attacker with the ability to manipulate DNS responses could direct the gem command towards a different domain due to unsanitize DNS responses when requesting the hostname of the rubygems server for a domain resulting in DNS hijacking vulnerability.