CVE-2012-2125

RubyGems <1.8.23 - Open Redirect

Title source: llm
STIX 2.1

Description

RubyGems before 1.8.23 can redirect HTTPS connections to HTTP, which makes it easier for remote attackers to observe or modify a gem during installation via a man-in-the-middle attack.

References (8)

Core 8
Core References
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/55381
Vendor Advisory vendor-advisory x_refsource_ubuntu
http://www.ubuntu.com/usn/USN-1582-1/
Vendor Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2013-1203.html
Patch mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2012/04/20/24
Vendor Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2013-1852.html
Vendor Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2013-1441.html

Scores

EPSS 0.0064
EPSS Percentile 70.6%

Details

Status published
Products (24)
rubygems/rubygems 1.8.0
rubygems/rubygems 1.8.1
rubygems/rubygems 1.8.2
rubygems/rubygems 1.8.3
rubygems/rubygems 1.8.4
rubygems/rubygems 1.8.5
rubygems/rubygems 1.8.6
rubygems/rubygems 1.8.7
rubygems/rubygems 1.8.8
rubygems/rubygems 1.8.9
... and 14 more
Published Oct 01, 2013
Tracked Since Feb 18, 2026