CVE-2012-2125
published 2013-10-01CVE-2012-2125: RubyGems before 1.8.23 can redirect HTTPS connections to HTTP, which makes it easier for remote attackers to observe or modify a gem during installation via a…
PriorityP424medium5.8CVSS 2.0
AVNACMAuNCPIPAN
EPSS
2.48%
82.7th percentile
RubyGems before 1.8.23 can redirect HTTPS connections to HTTP, which makes it easier for remote attackers to observe or modify a gem during installation via a man-in-the-middle attack.
Affected
28 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | rubygems | < rubygems 1.8.24-1 (bookworm) | rubygems 1.8.24-1 (bookworm) |
| rubygems | rubygems | <= 1.8.22 | — |
| rubygems | rubygems | — | — |
| rubygems | rubygems | — | — |
| rubygems | rubygems | — | — |
| rubygems | rubygems | — | — |
| rubygems | rubygems | — | — |
| rubygems | rubygems | — | — |
| rubygems | rubygems | — | — |
| rubygems | rubygems | — | — |
| rubygems | rubygems | — | — |
| rubygems | rubygems | — | — |
| rubygems | rubygems | — | — |
| rubygems | rubygems | — | — |
| rubygems | rubygems | — | — |
| rubygems | rubygems | — | — |
| rubygems | rubygems | — | — |
| rubygems | rubygems | — | — |
| rubygems | rubygems | — | — |
| rubygems | rubygems | — | — |
| rubygems | rubygems | — | — |
| rubygems | rubygems | — | — |
| rubygems | rubygems | — | — |
| rubygems | rubygems | — | — |
| rubygems | rubygems | >= 0 < 1.8.24-1 | 1.8.24-1 |
CVSS provenance
nvdv2.05.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:N
osv5.8MEDIUM
vendor_debian5.8MEDIUM
vendor_redhat5.8MEDIUM
vendor_ubuntu5.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
RubyGems HTTPS to HTTP redirect
ghsa·2022-05-17
CVE-2012-2125 [MEDIUM] RubyGems HTTPS to HTTP redirect
RubyGems HTTPS to HTTP redirect
RubyGems before 1.8.23 can redirect HTTPS connections to HTTP, which makes it easier for remote attackers to observe or modify a gem during installation via a man-in-the-middle attack.
OSV
RubyGems HTTPS to HTTP redirect
osv·2022-05-17
CVE-2012-2125 [MEDIUM] RubyGems HTTPS to HTTP redirect
RubyGems HTTPS to HTTP redirect
RubyGems before 1.8.23 can redirect HTTPS connections to HTTP, which makes it easier for remote attackers to observe or modify a gem during installation via a man-in-the-middle attack.
OSV
CVE-2012-2125: RubyGems before 1
osv·2013-10-01·CVSS 5.8
CVE-2012-2125 [MEDIUM] CVE-2012-2125: RubyGems before 1
RubyGems before 1.8.23 can redirect HTTPS connections to HTTP, which makes it easier for remote attackers to observe or modify a gem during installation via a man-in-the-middle attack.
Ubuntu
RubyGems vulnerabilities
vendor_ubuntu·2012-09-26·CVSS 5.8
CVE-2012-2125 [MEDIUM] RubyGems vulnerabilities
Title: RubyGems vulnerabilities
Summary: RubyGems could be made to download and install malicious gem files.
John Firebaugh discovered that the RubyGems remote gem fetcher did not properly
verify SSL certificates. A remote attacker could exploit this to perform a man
in the middle attack to alter gem files being downloaded for installation.
(CVE-2012-2126)
John Firebaugh discovered that the RubyGems remote gem fetcher allowed
redirection from HTTPS to HTTP. A remote attacker could exploit this to perform
a machine-in-the-middle attack to alter gem files being downloaded for
installation. (CVE-2012-2125)
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
Ruby vulnerabilities
vendor_ubuntu·2012-09-26·CVSS 5.0
CVE-2011-1005 [MEDIUM] Ruby vulnerabilities
Title: Ruby vulnerabilities
Summary: Several security issues were fixed in ruby1.9.1
It was discovered that Ruby incorrectly allowed untainted strings to be
modified in protective safe levels. An attacker could use this flaw to bypass
intended access restrictions. (CVE-2011-1005)
John Firebaugh discovered that the RubyGems remote gem fetcher did not properly
verify SSL certificates. A remote attacker could exploit this to perform a man
in the middle attack to alter gem files being downloaded for installation.
(CVE-2012-2126)
John Firebaugh discovered that the RubyGems remote gem fetcher allowed
redirection from HTTPS to HTTP. A remote attacker could exploit this to perform
a machine-in-the-middle attack to alter gem files being downloaded for
installation. (CVE-2012-2125)
Instructions
Red Hat
rubygems: Two security fixes in v1.8.23
vendor_redhat·2012-04-19·CVSS 5.8
CVE-2012-2125 [MEDIUM] rubygems: Two security fixes in v1.8.23
rubygems: Two security fixes in v1.8.23
RubyGems before 1.8.23 can redirect HTTPS connections to HTTP, which makes it easier for remote attackers to observe or modify a gem during installation via a man-in-the-middle attack.
Statement: The Red Hat Security Response Team has rated this issue as having moderate security impact in CloudForms 1.1. This issue is not currently planned to be addressed in future updates.
Package: rubygems (Red Hat Subscription Asset Manager) - Will not fix
Debian
CVE-2012-2125: rubygems - RubyGems before 1.8.23 can redirect HTTPS connections to HTTP, which makes it ea...
vendor_debian·2012·CVSS 5.8
CVE-2012-2125 [MEDIUM] CVE-2012-2125: rubygems - RubyGems before 1.8.23 can redirect HTTPS connections to HTTP, which makes it ea...
RubyGems before 1.8.23 can redirect HTTPS connections to HTTP, which makes it easier for remote attackers to observe or modify a gem during installation via a man-in-the-middle attack.
Scope: local
bookworm: resolved (fixed in 1.8.24-1)
bullseye: resolved (fixed in 1.8.24-1)
forky: resolved (fixed in 1.8.24-1)
sid: resolved (fixed in 1.8.24-1)
trixie: resolved (fixed in 1.8.24-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2012-2125, CVE-2012-2126 rubygems: Two security fixes in v1.8.23 [epel-5]
bugzilla·2012-04-20·CVSS 5.8
CVE-2012-2125 [MEDIUM] CVE-2012-2125, CVE-2012-2126 rubygems: Two security fixes in v1.8.23 [epel-5]
CVE-2012-2125, CVE-2012-2126 rubygems: Two security fixes in v1.8.23 [epel-5]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=securi
Bugzilla
CVE-2012-2125 CVE-2012-2126 rubygems: Two security fixes in v1.8.23
bugzilla·2012-04-20·CVSS 5.8
CVE-2012-2125 [MEDIUM] CVE-2012-2125 CVE-2012-2126 rubygems: Two security fixes in v1.8.23
CVE-2012-2125 CVE-2012-2126 rubygems: Two security fixes in v1.8.23
Two security flaws were corrected in upstream rubygems v1.8.23 version:
#1 RubyGems now disallows redirection from HTTPS to HTTP,
#2 RubyGems now verifies SSL connections.
References:
[1] https://github.com/rubygems/rubygems/blob/1.8/History.txt
Upstream patch:
[2] https://github.com/rubygems/rubygems/commit/d4c7eafb8efe1e13a7abf5be5a5b4548870b15b7
Discussion:
These issues affect the versions of the rubygems package, as shipped with Red Hat Enterprise Linux 6.
--
These issues affect the versions of the rubygems package, as shipped with Fedora release of 15 and 16. Please schedule the updates.
--
These issues affect the version of the rubygems package, as shipped with Fedora EPEL 5. Please schedule the update.
---
Bugzilla
CVE-2012-2125, CVE-2012-2126 rubygems: Two security fixes in v1.8.23 [fedora-16]
bugzilla·2012-04-20·CVSS 5.8
CVE-2012-2125 [MEDIUM] CVE-2012-2125, CVE-2012-2126 rubygems: Two security fixes in v1.8.23 [fedora-16]
CVE-2012-2125, CVE-2012-2126 rubygems: Two security fixes in v1.8.23 [fedora-16]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=sec
Bugzilla
CVE-2012-2125, CVE-2012-2126 rubygems: Two security fixes in v1.8.23 [fedora-all]
bugzilla·2012-04-20·CVSS 5.8
CVE-2012-2125 [MEDIUM] CVE-2012-2125, CVE-2012-2126 rubygems: Two security fixes in v1.8.23 [fedora-all]
CVE-2012-2125, CVE-2012-2126 rubygems: Two security fixes in v1.8.23 [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=se
http://rhn.redhat.com/errata/RHSA-2013-1203.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1441.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1852.htmlhttp://secunia.com/advisories/55381http://www.openwall.com/lists/oss-security/2012/04/20/24http://www.ubuntu.com/usn/USN-1582-1/https://bugzilla.redhat.com/show_bug.cgi?id=814718https://github.com/rubygems/rubygems/blob/1.8/History.txthttp://rhn.redhat.com/errata/RHSA-2013-1203.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1441.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1852.htmlhttp://secunia.com/advisories/55381http://www.openwall.com/lists/oss-security/2012/04/20/24http://www.ubuntu.com/usn/USN-1582-1/https://bugzilla.redhat.com/show_bug.cgi?id=814718https://github.com/rubygems/rubygems/blob/1.8/History.txt
2013-10-01
Published