RubyGems是RubyGems组织的一款Ruby程序包管理器,它主要用于发布和管理Ruby程序包。 RubyGems中存在安全漏洞,该漏洞源于程序提取gem或创建API请求时没有正确验证域名。远程攻击者可借助特制的DNS SRV记录利用该漏洞将请求重定向到任意域。以下版本受到影响:RubyGems 2.0.17之前2.0.x版本,2.2.5之前2.2.x版本,2.4.8之前2.4.x版本。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2012-2150 | xfsprogs xfs_metadump 本地信息泄露漏洞 | |
| CVE-2015-5161 | Zend ZendXml和Zend Framework XML外部实体注入漏洞 | |
| CVE-2015-5949 | VideoLAN VLC Media Player 缓冲区溢出漏洞 | |
| CVE-2015-3269 | Adobe LiveCycle Data Services Apache Flex BlazeDS 信息泄露漏洞 | |
| CVE-2015-5785 | Apple QuickTime 缓冲区溢出漏洞 | |
| CVE-2015-5786 | Apple QuickTime 缓冲区溢出漏洞 | |
| CVE-2015-6262 | Cisco Prime Infrastructure 跨站请求伪造漏洞 |
No comments yet