VDB
DEBIAN-CVE-2012-2125
DEBIAN-CVE-2012-2125
PUBLISHED
RubyGems before 1.8.23 can redirect HTTPS connections to HTTP, which makes it easier for remote attackers to observe or modify a gem during installation via a man-in-the-middle attack.
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Debian:12 | rubygems | 0, 0, 0 |
| Debian:13 | rubygems | 0, 0, 0 |
| Debian:11 | rubygems | 0, 0, 0 |
| Debian:14 | rubygems | 0, 0, 0 |
Timeline
- Oct 1, 2013 CVE Published
- Apr 28, 2026 CVE Updated