RubyGems 2.0.x before 2.0.16, 2.2.x before 2.2.4, and 2.4.x before 2.4.7 does not validate the hostname when fetching gems or making API requests, which allows remote attackers to redirect requests to arbitrary domains via a crafted DNS SRV record, aka a "DNS hijack attack."
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
Configuration 4 (hide)
|
Information
Published : 2015-06-24 07:59
Updated : 2019-04-22 10:48
NVD link : CVE-2015-3900
Mitre link : CVE-2015-3900
JSON object : View
CWE
CWE-254
7PK - Security Features
Products Affected
rubygems
- rubygems
ruby-lang
- ruby
redhat
- enterprise_linux
oracle
- solaris