Ecosyste.ms: Advisories
An open API service providing security vulnerability metadata for many open source software ecosystems.
Security Advisories: MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXd3NzktOHh3di05MzJ4
rbovirt uses the rest-client gem with SSL verification disabled
The rbovirt gem before 0.0.24 for Ruby uses the rest-client gem with SSL verification disabled, which allows remote attackers to conduct man-in-the-middle attacks via unspecified vectors.
Permalink: https://github.com/advisories/GHSA-ww79-8xwv-932xJSON: https://advisories.ecosyste.ms/api/v1/advisories/MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXd3NzktOHh3di05MzJ4
Source: GitHub Advisory Database
Origin: Unspecified
Severity: Moderate
Classification: General
Published: about 7 years ago
Updated: about 1 year ago
EPSS Percentage: 0.00168
EPSS Percentile: 0.53914
Identifiers: GHSA-ww79-8xwv-932x, CVE-2014-0036
References:
- https://nvd.nist.gov/vuln/detail/CVE-2014-0036
- https://bugzilla.redhat.com/show_bug.cgi?id=1058595
- http://lists.fedoraproject.org/pipermail/package-announce/2014-March/130148.html
- http://lists.fedoraproject.org/pipermail/package-announce/2014-March/130180.html
- http://seclists.org/oss-sec/2014/q1/509
- https://github.com/rubysec/ruby-advisory-db/blob/master/gems/rbovirt/CVE-2014-0036.yml
- https://github.com/advisories/GHSA-ww79-8xwv-932x
Affected Packages
rubygems:rbovirt
Dependent packages: 26Dependent repositories: 2,074
Downloads: 5,721,233 total
Affected Version Ranges: < 0.0.24
Fixed in: 0.0.24
All affected versions: 0.0.1, 0.0.2, 0.0.3, 0.0.4, 0.0.5, 0.0.6, 0.0.7, 0.0.8, 0.0.9, 0.0.10, 0.0.11, 0.0.12, 0.0.13, 0.0.14, 0.0.15, 0.0.16, 0.0.17, 0.0.18, 0.0.19, 0.0.20, 0.0.21, 0.0.22, 0.0.23
All unaffected versions: 0.0.24, 0.0.25, 0.0.26, 0.0.27, 0.0.28, 0.0.29, 0.0.30, 0.0.31, 0.0.32, 0.0.33, 0.0.34, 0.0.35, 0.0.36, 0.0.37, 0.0.38, 0.1.0, 0.1.1, 0.1.2, 0.1.3, 0.1.4, 0.1.5, 0.1.6, 0.1.7