CVE-2012-2125 : Detail

CVE-2012-2125

0.41%V3
Network
2013-10-01
15h00 +00:00
2014-01-07
12h57 +00:00
Notifications for a CVE
Stay informed of any changes for a specific CVE.
Notifications manage

CVE Descriptions

RubyGems before 1.8.23 can redirect HTTPS connections to HTTP, which makes it easier for remote attackers to observe or modify a gem during installation via a man-in-the-middle attack.

CVE Informations

Metrics

Metrics Score Severity CVSS Vector Source
V2 5.8 AV:N/AC:M/Au:N/C:P/I:P/A:N [email protected]

EPSS

EPSS is a scoring model that predicts the likelihood of a vulnerability being exploited.

EPSS Score

The EPSS model produces a probability score between 0 and 1 (0 and 100%). The higher the score, the greater the probability that a vulnerability will be exploited.

EPSS Percentile

The percentile is used to rank CVE according to their EPSS score. For example, a CVE in the 95th percentile according to its EPSS score is more likely to be exploited than 95% of other CVE. Thus, the percentile is used to compare the EPSS score of a CVE with that of other CVE.

Products Mentioned

Configuraton 0

Rubygems>>Rubygems >> Version To (including) 1.8.22

Rubygems>>Rubygems >> Version 1.8.0

Rubygems>>Rubygems >> Version 1.8.1

Rubygems>>Rubygems >> Version 1.8.2

Rubygems>>Rubygems >> Version 1.8.3

Rubygems>>Rubygems >> Version 1.8.4

Rubygems>>Rubygems >> Version 1.8.5

Rubygems>>Rubygems >> Version 1.8.6

Rubygems>>Rubygems >> Version 1.8.7

Rubygems>>Rubygems >> Version 1.8.8

Rubygems>>Rubygems >> Version 1.8.9

Rubygems>>Rubygems >> Version 1.8.10

Rubygems>>Rubygems >> Version 1.8.11

Rubygems>>Rubygems >> Version 1.8.12

Rubygems>>Rubygems >> Version 1.8.13

Rubygems>>Rubygems >> Version 1.8.14

Rubygems>>Rubygems >> Version 1.8.15

Rubygems>>Rubygems >> Version 1.8.16

Rubygems>>Rubygems >> Version 1.8.17

Rubygems>>Rubygems >> Version 1.8.18

Rubygems>>Rubygems >> Version 1.8.19

Rubygems>>Rubygems >> Version 1.8.20

Rubygems>>Rubygems >> Version 1.8.21

Redhat>>Openshift >> Version 1.2.2

Canonical>>Ubuntu_linux >> Version 12.04

References

http://secunia.com/advisories/55381
Tags : third-party-advisory, x_refsource_SECUNIA
http://www.ubuntu.com/usn/USN-1582-1/
Tags : vendor-advisory, x_refsource_UBUNTU
http://rhn.redhat.com/errata/RHSA-2013-1203.html
Tags : vendor-advisory, x_refsource_REDHAT
http://www.openwall.com/lists/oss-security/2012/04/20/24
Tags : mailing-list, x_refsource_MLIST
http://rhn.redhat.com/errata/RHSA-2013-1852.html
Tags : vendor-advisory, x_refsource_REDHAT
http://rhn.redhat.com/errata/RHSA-2013-1441.html
Tags : vendor-advisory, x_refsource_REDHAT