CVE-2017-0902
HIGH severity · CVSS 8.1 · CWE-350
8.1CVSS HIGH
Summary
RubyGems version 2.6.12 and earlier is vulnerable to a DNS hijacking vulnerability that allows a MITM attacker to force the RubyGems client to download and install gems from a server that the attacker controls.
Impact & exploitability
Attack vectorNetwork
Attack complexityHigh
Privileges requiredNone
User interactionNone
Confidentiality impactHigh
Integrity impactHigh
Availability impactHigh
Exploit probability (EPSS)5%
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products we track (1)
Recommendation
Apply the vendor fix promptly. Open any affected product above for its exact safe version.
Official patch: http://blog.rubygems.org/2017/08/27/2.6.13-released.html ↗
Additional information
- NVD record
- http://blog.rubygems.org/2017/08/27/2.6.13-released.htmlPatch
- https://github.com/rubygems/rubygems/commit/8d91516fb7037ecfb27622f605dc40245e0f8d32Patch
- http://www.securityfocus.com/bid/100586Advisory
- http://www.securitytracker.com/id/1039249Advisory
- https://access.redhat.com/errata/RHSA-2017:3485Advisory
- https://access.redhat.com/errata/RHSA-2018:0378Advisory
- https://access.redhat.com/errata/RHSA-2018:0583Advisory
- https://access.redhat.com/errata/RHSA-2018:0585Advisory