← Back

CVE-2012-2125

nvd nist
Published: Oct 1, 2013Modified: Apr 29, 2026

JSON object

Loading...
5.8
Vector
AV:N/AC:M/Au:N/C:P/I:P/A:N
Exploitability: 8.6 / Impact: 4.9
Source: NVD

Description

RubyGems before 1.8.23 can redirect HTTPS connections to HTTP, which makes it easier for remote attackers to observe or modify a gem during installation via a man-in-the-middle attack.

Affected (23)

Products: Rubygems: Rubygems
1 product
Rubygems
Configuration A
23 vulnerable · 2 platform
Vulnerable SoftwareAffected Versions
Rubygems
Up to 1.8.22
Version 1.8.0
Version 1.8.10
Version 1.8.11
Version 1.8.12
Version 1.8.13
Version 1.8.14
Version 1.8.15
Version 1.8.16
Version 1.8.17
Version 1.8.18
Version 1.8.19
Version 1.8.1
Version 1.8.20
Version 1.8.21
Version 1.8.2
Version 1.8.3
Version 1.8.4
Version 1.8.5
Version 1.8.6
Version 1.8.7
Version 1.8.8
Version 1.8.9
Running on/withPlatform Versions
Canonical
Ubuntu Linux
Version 12.04
Redhat
Openshift
Version 1.2.2

References (16)

Source: secalert@redhat.com
Vendor Advisory
Source: secalert@redhat.com
Source: secalert@redhat.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Patch
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Patch
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.