RubyGems 2.0.x before 2.0.16, 2.2.x before 2.2.4, and 2.4.x before 2.4.7 does not validate the hostname when fetching gems or making API requests, which allows remote attackers to redirect requests to arbitrary domains via a crafted DNS SRV record, aka a "DNS hijack attack."
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
Configuration 4 (hide)
|
History
No history.
Information
Published : 2015-06-24 14:59
Updated : 2019-04-22 17:48
NVD link : CVE-2015-3900
Mitre link : CVE-2015-3900
CVE.ORG link : CVE-2015-3900
JSON object : View
Products Affected
rubygems
- rubygems
ruby-lang
- ruby
redhat
- enterprise_linux
oracle
- solaris
CWE
CWE-254
7PK - Security Features