CVE-2015-3900

Source
https://cve.org/CVERecord?id=CVE-2015-3900
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2015-3900.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2015-3900
Aliases
Downstream
DEBIAN (1)
MGASA (1)
openSUSE (2)
RHSA (1)
SUSE (1)
Related
Withdrawn
2026-01-27T04:15:01Z
Published
2015-06-24T14:59:01Z
Modified
2026-04-16T01:38:56Z
Summary
[none]
Details

RubyGems 2.0.x before 2.0.16, 2.2.x before 2.2.4, and 2.4.x before 2.4.7 does not validate the hostname when fetching gems or making API requests, which allows remote attackers to redirect requests to arbitrary domains via a crafted DNS SRV record, aka a "DNS hijack attack."

References

Affected packages