Vulnerability Name:
CVE-2012-2125 (CCN-87741)
Assigned:
2012-04-19
Published:
2012-04-19
Updated:
2014-01-14
Summary:
RubyGems before 1.8.23 can redirect HTTPS connections to HTTP, which makes it easier for remote attackers to observe or modify a gem during installation via a man-in-the-middle attack.
CVSS v3 Severity:
6.5 Medium
(CCN CVSS v3.1 Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
)
Exploitability Metrics:
Attack Vector (AV):
Network
Attack Complexity (AC):
Low
Privileges Required (PR):
None
User Interaction (UI):
None
Scope:
Scope (S):
Unchanged
Impact Metrics:
Confidentiality (C):
Low
Integrity (I):
Low
Availibility (A):
None
CVSS v2 Severity:
5.8 Medium
(CVSS v2 Vector:
AV:N/AC:M/Au:N/C:P/I:P/A:N
)
4.3 Medium
(Temporal CVSS v2 Vector:
AV:N/AC:M/Au:N/C:P/I:P/A:N/E:U/RL:OF/RC:C
)
Exploitability Metrics:
Access Vector (AV):
Network
Access Complexity (AC):
Medium
Authentication (Au):
None
Impact Metrics:
Confidentiality (C):
Partial
Integrity (I):
Partial
Availibility (A):
None
5.8 Medium
(CCN CVSS v2 Vector:
AV:N/AC:M/Au:N/C:P/I:P/A:N
)
4.3 Medium
(CCN Temporal CVSS v2 Vector:
AV:N/AC:M/Au:N/C:P/I:P/A:N/E:U/RL:OF/RC:C
)
Exploitability Metrics:
Access Vector (AV):
Network
Access Complexity (AC):
Medium
Athentication (Au):
None
Impact Metrics:
Confidentiality (C):
Partial
Integrity (I):
Partial
Availibility (A):
None
4.0 Medium
(REDHAT CVSS v2 Vector:
AV:N/AC:H/Au:N/C:P/I:P/A:N
)
3.0 Low
(REDHAT Temporal CVSS v2 Vector:
AV:N/AC:H/Au:N/C:P/I:P/A:N/E:U/RL:OF/RC:C
)
Exploitability Metrics:
Access Vector (AV):
Network
Access Complexity (AC):
High
Authentication (Au):
None
Impact Metrics:
Confidentiality (C):
Partial
Integrity (I):
Partial
Availibility (A):
None
Vulnerability Type:
CWE-Other
Vulnerability Consequences:
Bypass Security
References:
Source: MITRE
Type: CNA
CVE-2012-2125
Source: REDHAT
Type: Vendor Advisory
RHSA-2013:1203
Source: CCN
Type: RHSA-2013-1441
Moderate: rubygems security update
Source: REDHAT
Type: UNKNOWN
RHSA-2013:1441
Source: CCN
Type: RHSA-2013-1852
Moderate: Red Hat Enterprise MRG Grid 2.4 security update
Source: REDHAT
Type: UNKNOWN
RHSA-2013:1852
Source: SECUNIA
Type: UNKNOWN
55381
Source: MLIST
Type: Patch
[oss-security] 20120420 Re: CVE Request -- rubygems: Two security fixes in upstream v1.8.23 version
Source: CCN
Type: BID-55680
RubyGems CVE-2012-2125 URI Redirection Vulnerability
Source: UBUNTU
Type: Vendor Advisory
USN-1582-1
Source: CCN
Type: Red Hat Bugzilla Bug 814718
(CVE-2012-2125, CVE-2012-2126) CVE-2012-2125 CVE-2012-2126 rubygems: Two security fixes in v1.8.23
Source: MISC
Type: Patch
https://bugzilla.redhat.com/show_bug.cgi?id=814718
Source: XF
Type: UNKNOWN
rubygems-cve20122125-sec-bypass(87741)
Source: CCN
Type: RubyGems GIT Repository
RubyGems
Source: CONFIRM
Type: UNKNOWN
https://github.com/rubygems/rubygems/blob/1.8/History.txt
Source: CCN
Type: WhiteSource Vulnerability Database
CVE-2012-2125
Vulnerable Configuration:
Configuration 1
:
cpe:/a:rubygems:rubygems:1.8.0:*:*:*:*:*:*:*
OR
cpe:/a:rubygems:rubygems:1.8.1:*:*:*:*:*:*:*
OR
cpe:/a:rubygems:rubygems:1.8.2:*:*:*:*:*:*:*
OR
cpe:/a:rubygems:rubygems:1.8.3:*:*:*:*:*:*:*
OR
cpe:/a:rubygems:rubygems:1.8.4:*:*:*:*:*:*:*
OR
cpe:/a:rubygems:rubygems:1.8.5:*:*:*:*:*:*:*
OR
cpe:/a:rubygems:rubygems:1.8.6:*:*:*:*:*:*:*
OR
cpe:/a:rubygems:rubygems:1.8.7:*:*:*:*:*:*:*
OR
cpe:/a:rubygems:rubygems:1.8.8:*:*:*:*:*:*:*
OR
cpe:/a:rubygems:rubygems:1.8.9:*:*:*:*:*:*:*
OR
cpe:/a:rubygems:rubygems:1.8.10:*:*:*:*:*:*:*
OR
cpe:/a:rubygems:rubygems:1.8.11:*:*:*:*:*:*:*
OR
cpe:/a:rubygems:rubygems:1.8.12:*:*:*:*:*:*:*
OR
cpe:/a:rubygems:rubygems:1.8.13:*:*:*:*:*:*:*
OR
cpe:/a:rubygems:rubygems:1.8.14:*:*:*:*:*:*:*
OR
cpe:/a:rubygems:rubygems:1.8.15:*:*:*:*:*:*:*
OR
cpe:/a:rubygems:rubygems:1.8.16:*:*:*:*:*:*:*
OR
cpe:/a:rubygems:rubygems:1.8.17:*:*:*:*:*:*:*
OR
cpe:/a:rubygems:rubygems:1.8.18:*:*:*:*:*:*:*
OR
cpe:/a:rubygems:rubygems:1.8.19:*:*:*:*:*:*:*
OR
cpe:/a:rubygems:rubygems:1.8.20:*:*:*:*:*:*:*
OR
cpe:/a:rubygems:rubygems:1.8.21:*:*:*:*:*:*:*
OR
cpe:/a:rubygems:rubygems:*:*:*:*:*:*:*:*
(Version <= 1.8.22)
AND
cpe:/a:redhat:openshift:1.2.2:-:enterprise:*:*:*:*:*
OR
cpe:/o:canonical:ubuntu_linux:12.04:-:lts:*:*:*:*:*
Configuration RedHat 1
:
cpe:/o:redhat:enterprise_linux:6:*:*:*:*:*:*:*
Configuration RedHat 2
:
cpe:/o:redhat:enterprise_linux:6::client:*:*:*:*:*
Configuration RedHat 3
:
cpe:/o:redhat:enterprise_linux:6::computenode:*:*:*:*:*
Configuration RedHat 4
:
cpe:/o:redhat:enterprise_linux:6::server:*:*:*:*:*
Configuration RedHat 5
:
cpe:/o:redhat:enterprise_linux:6::workstation:*:*:*:*:*
Configuration CCN 1
:
cpe:/a:rubyforge:rubygems:0.8.11:*:*:*:*:*:*:*
AND
cpe:/o:redhat:enterprise_linux:6::server:*:*:*:*:*
OR
cpe:/o:redhat:enterprise_linux:6::workstation:*:*:*:*:*
OR
cpe:/o:redhat:enterprise_linux_desktop:6:*:*:*:*:*:*:*
OR
cpe:/o:redhat:enterprise_linux_hpc_node:6:*:*:*:*:*:*:*
Denotes that component is vulnerable
Oval Definitions
Definition ID
Class
Title
Last Modified
oval:org.mitre.oval:def:18016
P
USN-1582-1 -- rubygems vulnerabilities
2014-07-21
oval:org.mitre.oval:def:17580
P
USN-1583-1 -- ruby1.9.1 vulnerabilities
2014-06-30
oval:com.redhat.rhsa:def:20131441
P
RHSA-2013:1441: rubygems security update (Moderate)
2013-10-17
oval:com.ubuntu.xenial:def:201221250000000
V
CVE-2012-2125 on Ubuntu 16.04 LTS (xenial) - low.
2013-10-01
oval:com.ubuntu.precise:def:20122125000
V
CVE-2012-2125 on Ubuntu 12.04 LTS (precise) - low.
2013-10-01
oval:com.ubuntu.artful:def:20122125000
V
CVE-2012-2125 on Ubuntu 17.10 (artful) - low.
2013-10-01
oval:com.ubuntu.trusty:def:20122125000
V
CVE-2012-2125 on Ubuntu 14.04 LTS (trusty) - low.
2013-10-01
oval:com.ubuntu.cosmic:def:201221250000000
V
CVE-2012-2125 on Ubuntu 18.10 (cosmic) - low.
2013-10-01
oval:com.ubuntu.bionic:def:20122125000
V
CVE-2012-2125 on Ubuntu 18.04 LTS (bionic) - low.
2013-10-01
oval:com.ubuntu.xenial:def:20122125000
V
CVE-2012-2125 on Ubuntu 16.04 LTS (xenial) - low.
2013-10-01
oval:com.ubuntu.bionic:def:201221250000000
V
CVE-2012-2125 on Ubuntu 18.04 LTS (bionic) - low.
2013-10-01
oval:com.ubuntu.cosmic:def:20122125000
V
CVE-2012-2125 on Ubuntu 18.10 (cosmic) - low.
2013-10-01
BACK
rubygems
rubygems 1.8.0
rubygems
rubygems 1.8.1
rubygems
rubygems 1.8.2
rubygems
rubygems 1.8.3
rubygems
rubygems 1.8.4
rubygems
rubygems 1.8.5
rubygems
rubygems 1.8.6
rubygems
rubygems 1.8.7
rubygems
rubygems 1.8.8
rubygems
rubygems 1.8.9
rubygems
rubygems 1.8.10
rubygems
rubygems 1.8.11
rubygems
rubygems 1.8.12
rubygems
rubygems 1.8.13
rubygems
rubygems 1.8.14
rubygems
rubygems 1.8.15
rubygems
rubygems 1.8.16
rubygems
rubygems 1.8.17
rubygems
rubygems 1.8.18
rubygems
rubygems 1.8.19
rubygems
rubygems 1.8.20
rubygems
rubygems 1.8.21
rubygems
rubygems *
redhat
openshift 1.2.2 -
canonical
ubuntu linux 12.04 -
rubyforge
rubygems 0.8.11
redhat
enterprise linux 6
redhat
enterprise linux 6
redhat
enterprise linux desktop 6
redhat
enterprise linux hpc node 6