CVE-2015-3900: Medium severity ruby vulnerability
RubyGems 2.0.x before 2.0.16, 2.2.x before 2.2.4, and 2.4.x before 2.4.7 does not validate the hostname when fetching gems or making API requests, which allows remote attackers to redirect requests to arbitrary domains via a crafted DNS SRV record, aka a "DNS hijack attack."
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2015-3900?
CVE-2015-3900 has a moderate severity rating due to the potential for DNS hijack attacks.
How do I fix CVE-2015-3900?
To fix CVE-2015-3900, upgrade RubyGems to version 2.0.16, 2.2.4, or 2.4.7 or later.
What versions are affected by CVE-2015-3900?
CVE-2015-3900 affects RubyGems versions 2.0.x before 2.0.16, 2.2.x before 2.2.4, and 2.4.x before 2.4.7.
What does CVE-2015-3900 exploit?
CVE-2015-3900 exploits vulnerabilities in RubyGems' hostname validation when fetching gems or making API requests.
Who can be impacted by CVE-2015-3900?
Users of RubyGems versions prior to the patched versions are at risk of being impacted by CVE-2015-3900.