CVE-2015-4020 describes a DNS hijack vulnerability in RubyGems versions 2.0.x, 2.2.x, and 2.4.x, affecting RubyGems itself and Oracle Solaris. This flaw allows remote attackers to redirect gem fetching and API requests to arbitrary domains through crafted DNS SRV records, stemming from an incomplete fix for a previous vulnerability. With a CVSS score of 4.3 (medium severity), it requires moderate attack complexity and primarily impacts integrity, with no confidentiality or availability impact. There is no evidence of active exploitation, public exploit code, or inclusion in the KEV catalog, though it has received some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
11.3CPE matchmatch criteria | cpe:2.3:o:oracle:solaris:11.3:*:*:*:*:*:*:* | ||
2.0.0CPE matchmatch criteria | cpe:2.3:a:rubygems:rubygems:2.0.0:*:*:*:*:*:*:* | ||
2.0.0CPE matchmatch criteria | cpe:2.3:a:rubygems:rubygems:2.0.0:preview2:*:*:*:*:*:* | ||
2.0.0CPE matchmatch criteria | cpe:2.3:a:rubygems:rubygems:2.0.0:preview2.1:*:*:*:*:*:* | ||
2.0.0CPE matchmatch criteria | cpe:2.3:a:rubygems:rubygems:2.0.0:preview2.2:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:N/I:P/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.