VDB

DEBIAN-CVE-2012-2125

DEBIAN-CVE-2012-2125 PUBLISHED

RubyGems before 1.8.23 can redirect HTTPS connections to HTTP, which makes it easier for remote attackers to observe or modify a gem during installation via a man-in-the-middle attack.

Affected Products

VendorProductVersions
Debian:12rubygems0, 0, 0
Debian:13rubygems0, 0, 0
Debian:11rubygems0, 0, 0
Debian:14rubygems0, 0, 0

Timeline

  • Oct 1, 2013 CVE Published
  • Apr 28, 2026 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›