CVE-2012-2126Rubygems vulnerability

CWE-31012 documents7 sources
Severity
4.3MEDIUMNVD
EPSS
0.3%
top 49.30%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedOct 1
Latest updateMay 17

Description

RubyGems before 1.8.23 does not verify an SSL certificate, which allows remote attackers to modify a gem during installation via a man-in-the-middle attack.

CVSS vector

AV:N/AC:M/C:N/I:P/A:NExploitability: 8.6 | Impact: 2.9

Affected Packages3 packages

debiandebian/rubygems< rubygems 1.8.24-1 (bookworm)
Debianrubygems/rubygems< 1.8.24-1+3
NVDrubygems/rubygems1.8.22+22

Patches

🔴Vulnerability Details

3
GHSA
RubyGems does not verify SSL certificate2022-05-17
OSV
RubyGems does not verify SSL certificate2022-05-17
OSV
CVE-2012-2126: RubyGems before 12013-10-01

📋Vendor Advisories

4
Ubuntu
RubyGems vulnerabilities2012-09-26
Ubuntu
Ruby vulnerabilities2012-09-26
Red Hat
rubygems: Two security fixes in v1.8.232012-04-19
Debian
CVE-2012-2126: rubygems - RubyGems before 1.8.23 does not verify an SSL certificate, which allows remote a...2012

💬Community

4
Bugzilla
CVE-2012-2125, CVE-2012-2126 rubygems: Two security fixes in v1.8.23 [epel-5]2012-04-20
Bugzilla
CVE-2012-2125 CVE-2012-2126 rubygems: Two security fixes in v1.8.232012-04-20
Bugzilla
CVE-2012-2125, CVE-2012-2126 rubygems: Two security fixes in v1.8.23 [fedora-16]2012-04-20
Bugzilla
CVE-2012-2125, CVE-2012-2126 rubygems: Two security fixes in v1.8.23 [fedora-all]2012-04-20