Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2015-4020


RubyGems 2.0.x before 2.0.17, 2.2.x before 2.2.5, and 2.4.x before 2.4.8 does not validate the hostname when fetching gems or making API requests, which allows remote attackers to redirect requests to arbitrary domains via a crafted DNS SRV record with a domain that is suffixed with the original domain name, aka a "DNS hijack attack." NOTE: this vulnerability exists because to an incomplete fix for CVE-2015-3900.


Published

2015-08-25T17:59:01.760

Last Modified

2025-04-12T10:46:40.837

Status

Deferred

Source

[email protected]

Severity

CVSSv2: 4.3 (MEDIUM)

CVSSv2 Vector

AV:N/AC:M/Au:N/C:N/I:P/A:N

  • Access Vector: NETWORK
  • Access Complexity: MEDIUM
  • Authentication: NONE
  • Confidentiality Impact: NONE
  • Integrity Impact: PARTIAL
  • Availability Impact: NONE
Exploitability Score

8.6

Impact Score

2.9

Weaknesses
  • Type: Primary
    CWE-20

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System oracle solaris 11.3 Yes
Application rubygems rubygems 2.0.0 Yes
Application rubygems rubygems 2.0.0 Yes
Application rubygems rubygems 2.0.0 Yes
Application rubygems rubygems 2.0.0 Yes
Application rubygems rubygems 2.0.0 Yes
Application rubygems rubygems 2.0.0 Yes
Application rubygems rubygems 2.0.1 Yes
Application rubygems rubygems 2.0.2 Yes
Application rubygems rubygems 2.0.3 Yes
Application rubygems rubygems 2.0.4 Yes
Application rubygems rubygems 2.0.5 Yes
Application rubygems rubygems 2.0.6 Yes
Application rubygems rubygems 2.0.7 Yes
Application rubygems rubygems 2.0.8 Yes
Application rubygems rubygems 2.0.9 Yes
Application rubygems rubygems 2.0.10 Yes
Application rubygems rubygems 2.0.11 Yes
Application rubygems rubygems 2.0.12 Yes
Application rubygems rubygems 2.0.13 Yes
Application rubygems rubygems 2.0.14 Yes
Application rubygems rubygems 2.0.15 Yes
Application rubygems rubygems 2.0.16 Yes
Application rubygems rubygems 2.2.0 Yes
Application rubygems rubygems 2.2.1 Yes
Application rubygems rubygems 2.2.2 Yes
Application rubygems rubygems 2.2.3 Yes
Application rubygems rubygems 2.2.4 Yes
Application rubygems rubygems 2.4.0 Yes
Application rubygems rubygems 2.4.1 Yes
Application rubygems rubygems 2.4.2 Yes
Application rubygems rubygems 2.4.3 Yes
Application rubygems rubygems 2.4.4 Yes
Application rubygems rubygems 2.4.5 Yes
Application rubygems rubygems 2.4.6 Yes
Application rubygems rubygems 2.4.7 Yes

References