{"id":"GHSA-qv62-xfj6-32xm","summary":"RubyGems Improper Input Validation vulnerability","details":"RubyGems 2.0.x before 2.0.17, 2.2.x before 2.2.5, and 2.3.x before 2.4.8 does not validate the hostname when fetching gems or making API requests, which allows remote attackers to redirect requests to arbitrary domains via a crafted DNS SRV record with a domain that is suffixed with the original domain name, aka a \"DNS hijack attack.\"\n\nNOTE: this vulnerability exists because of an incomplete fix for CVE-2015-3900.","aliases":["CVE-2015-4020"],"modified":"2024-12-02T05:50:33.753196Z","published":"2022-05-17T00:16:50Z","database_specific":{"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2023-05-04T21:14:40Z","nvd_published_at":"2015-08-25T17:59:00Z","cwe_ids":["CWE-20"]},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2015-4020"},{"type":"WEB","url":"https://github.com/rubygems/rubygems/commit/5c7bfb5"},{"type":"PACKAGE","url":"https://github.com/rubygems/rubygems"},{"type":"WEB","url":"https://github.com/rubysec/ruby-advisory-db/blob/master/gems/rubygems-update/CVE-2015-4020.yml"},{"type":"WEB","url":"https://puppet.com/security/cve/CVE-2015-3900"},{"type":"WEB","url":"https://web.archive.org/web/20200228084212/http://www.securityfocus.com/bid/75431"},{"type":"WEB","url":"https://web.archive.org/web/20200228085830/https://puppet.com/security/cve/CVE-2015-3900"},{"type":"WEB","url":"https://www.trustwave.com/Resources/Security-Advisories/Advisories/TWSL2015-009/?fid=6478"},{"type":"WEB","url":"https://www.trustwave.com/Resources/SpiderLabs-Blog/Attacking-Ruby-Gem-Security-with-CVE-2015-3900"},{"type":"WEB","url":"http://blog.rubygems.org/2015/06/08/2.2.5-released.html"},{"type":"WEB","url":"http://blog.rubygems.org/2015/06/08/2.4.8-released.html"},{"type":"WEB","url":"http://www.oracle.com/technetwork/topics/security/bulletinoct2015-2511968.html"},{"type":"WEB","url":"http://www.securityfocus.com/bid/75431"}],"affected":[{"package":{"name":"rubygems-update","ecosystem":"RubyGems","purl":"pkg:gem/rubygems-update"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.0.17"}]}],"versions":["0.8.10","0.8.11","0.8.3","0.8.4","0.8.5","0.8.6","0.8.8","0.9.0","0.9.1","0.9.2","0.9.3","0.9.4","0.9.5","1.0.0","1.0.1","1.1.0","1.1.1","1.2.0","1.3.0","1.3.1","1.3.2","1.3.3","1.3.4","1.3.5","1.3.6","1.3.7","1.4.0","1.4.1","1.4.2","1.5.0","1.5.2","1.5.3","1.6.0","1.6.1","1.6.2","1.7.0","1.7.1","1.7.2","1.8.0","1.8.1","1.8.10","1.8.11","1.8.12","1.8.13","1.8.14","1.8.15","1.8.16","1.8.17","1.8.18","1.8.19","1.8.2","1.8.20","1.8.21","1.8.22","1.8.23","1.8.23.2","1.8.24","1.8.25","1.8.26","1.8.27","1.8.28","1.8.29","1.8.3","1.8.30","1.8.4","1.8.5","1.8.6","1.8.7","1.8.8","1.8.9","2.0.0","2.0.0.preview2","2.0.0.preview2.1","2.0.0.preview2.2","2.0.0.rc.1","2.0.0.rc.2","2.0.10","2.0.11","2.0.12","2.0.13","2.0.14","2.0.15","2.0.16","2.0.2","2.0.3","2.0.4","2.0.5","2.0.6","2.0.7","2.0.8","2.0.9"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-qv62-xfj6-32xm/GHSA-qv62-xfj6-32xm.json"}},{"package":{"name":"rubygems-update","ecosystem":"RubyGems","purl":"pkg:gem/rubygems-update"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.1.0.rc.1"},{"fixed":"2.2.5"}]}],"versions":["2.1.0","2.1.0.rc.1","2.1.0.rc.2","2.1.1","2.1.10","2.1.11","2.1.2","2.1.3","2.1.4","2.1.5","2.1.6","2.1.7","2.1.8","2.1.9","2.2.0","2.2.0.rc.1","2.2.1","2.2.2","2.2.3","2.2.4"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-qv62-xfj6-32xm/GHSA-qv62-xfj6-32xm.json"}},{"package":{"name":"rubygems-update","ecosystem":"RubyGems","purl":"pkg:gem/rubygems-update"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.3.0"},{"fixed":"2.4.8"}]}],"versions":["2.3.0","2.4.0","2.4.1","2.4.2","2.4.3","2.4.4","2.4.5","2.4.6","2.4.7"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-qv62-xfj6-32xm/GHSA-qv62-xfj6-32xm.json"}}],"schema_version":"1.9.0"}