First published: Wed Sep 04 2013(Updated: )
RubyGems is the Ruby standard for publishing and managing third-party<br>libraries.<br>It was found that, when using RubyGems, the connection could be redirected<br>from HTTPS to HTTP. This could lead to a user believing they are installing<br>a gem via HTTPS, when the connection may have been silently downgraded to<br>HTTP. (CVE-2012-2125)<br>It was found that RubyGems did not verify SSL connections. This could lead<br>to man-in-the-middle attacks. (CVE-2012-2126)<br>All users of Red Hat OpenShift Enterprise 1.2.2 are advised to upgrade to<br>this updated package, which corrects these issues.<br>
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/rubygems | <1.8.24-4.el6 | 1.8.24-4.el6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.