CVE-2017-0902: High severity Rubygems RubyGems vulnerability
Last updated 11 July 2025
Other sources
RubyGems version 2.6.12 and earlier is vulnerable to a DNS hijacking vulnerability that allows a MITM attacker to force the RubyGems client to download and install gems from a server that the attacker controls.
Upstream patches:
https://github.com/rubygems/rubygems/commit/8d91516fb7037ecfb27622f605dc40245e0f8d32
Bug report:
https://hackerone.com/reports/218088
External References:
http://blog.rubygems.org/2017/08/27/2.6.13-released.html
— Red Hat
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2017-0902?
CVE-2017-0902 is a DNS hijacking vulnerability in RubyGems version 2.6.12 and earlier.
How does CVE-2017-0902 work?
CVE-2017-0902 allows a MITM attacker to force the RubyGems client to download and install gems from a server that the attacker controls.
What is the severity of CVE-2017-0902?
CVE-2017-0902 has a severity score of 8.1 (high).
Which software versions are affected by CVE-2017-0902?
RubyGems version 2.6.12 and earlier are affected by CVE-2017-0902.
How do I fix CVE-2017-0902?
To fix CVE-2017-0902, upgrade to RubyGems version 2.6.13 or later.