CVE-2012-2125
01.10.2013, 17:55
RubyGems before 1.8.23 can redirect HTTPS connections to HTTP, which makes it easier for remote attackers to observe or modify a gem during installation via a man-in-the-middle attack.Enginsight
| Vendor | Product | Version |
|---|---|---|
| rubygems | rubygems | 𝑥 ≤ 1.8.22 |
| rubygems | rubygems | 1.8.0 |
| rubygems | rubygems | 1.8.1 |
| rubygems | rubygems | 1.8.2 |
| rubygems | rubygems | 1.8.3 |
| rubygems | rubygems | 1.8.4 |
| rubygems | rubygems | 1.8.5 |
| rubygems | rubygems | 1.8.6 |
| rubygems | rubygems | 1.8.7 |
| rubygems | rubygems | 1.8.8 |
| rubygems | rubygems | 1.8.9 |
| rubygems | rubygems | 1.8.10 |
| rubygems | rubygems | 1.8.11 |
| rubygems | rubygems | 1.8.12 |
| rubygems | rubygems | 1.8.13 |
| rubygems | rubygems | 1.8.14 |
| rubygems | rubygems | 1.8.15 |
| rubygems | rubygems | 1.8.16 |
| rubygems | rubygems | 1.8.17 |
| rubygems | rubygems | 1.8.18 |
| rubygems | rubygems | 1.8.19 |
| rubygems | rubygems | 1.8.20 |
| rubygems | rubygems | 1.8.21 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| jruby |
| ||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| ruby1.9.1 |
| ||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| rubygems |
|
References