Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2015-4020

18
FAUCET Score

CVE-2015-4020 describes a DNS hijack vulnerability in RubyGems versions 2.0.x, 2.2.x, and 2.4.x, affecting RubyGems itself and Oracle Solaris. This flaw allows remote attackers to redirect gem fetching and API requests to arbitrary domains through crafted DNS SRV records, stemming from an incomplete fix for a previous vulnerability. With a CVSS score of 4.3 (medium severity), it requires moderate attack complexity and primarily impacts integrity, with no confidentiality or availability impact. There is no evidence of active exploitation, public exploit code, or inclusion in the KEV catalog, though it has received some community discussion and media coverage.

Impacted Technologies

VendorProductVersion(s)CPE
11.3CPE matchmatch criteria
cpe:2.3:o:oracle:solaris:11.3:*:*:*:*:*:*:*
2.0.0CPE matchmatch criteria
cpe:2.3:a:rubygems:rubygems:2.0.0:*:*:*:*:*:*:*
2.0.0CPE matchmatch criteria
cpe:2.3:a:rubygems:rubygems:2.0.0:preview2:*:*:*:*:*:*
2.0.0CPE matchmatch criteria
cpe:2.3:a:rubygems:rubygems:2.0.0:preview2.1:*:*:*:*:*:*
2.0.0CPE matchmatch criteria
cpe:2.3:a:rubygems:rubygems:2.0.0:preview2.2:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 2.0

4.3MEDIUM

AV:N/AC:M/Au:N/C:N/I:P/A:N

Confidentiality Impact
NONE
Integrity Impact
PARTIAL
Availability Impact
NONE
Access Vector
NETWORK
Access Complexity
MEDIUM
Authentication
NONE
Exploitability Score
8.6
Impact Score
2.9
CvssVersion
2.0

Exploit Intelligence

EPSS Score
3.46%
Probability of exploitation in next 30 days
EPSS Percentile
87.8%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0346 is in the 83rd percentile among its peer group of 19,956 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (3)

rubygemspatch availablevia ghsa
Product: rubygems-updateFixed in: 2.0.17
rubygemspatch availablevia ghsa
Product: rubygems-updateFixed in: 2.2.5
rubygemspatch availablevia ghsa
Product: rubygems-updateFixed in: 2.4.8

Vendor Advisories (2)

rubygemsGHSA-qv62-xfj6-32xmmedium

RubyGems Improper Input Validation vulnerability

May 17, 2022
redhatCVE-2015-4020Important

rubygems: incomplete fix for CVE-2015-3900

May 18, 2015

References

blog.rubygems.org / 2015/06/08/2.2.5-released.html
Vendor Advisory
blog.rubygems.org / 2015/06/08/2.4.8-released.html
Vendor Advisory
github.com / rubygems/rubygems/commit/5c7bfb5
puppet.com / security/cve/CVE-2015-3900
trustwave.com / Resources/Security-Advisories/Advisories/TWSL2015-009
Third Party Advisory
trustwave.com / Resources/SpiderLabs-Blog/Attacking-Ruby-Gem-Security-with-CVE-2015-3900
Third Party Advisory
oracle.com / technetwork/topics/security/bulletinoct2015-2511968.html
Third Party Advisory
securityfocus.com / bid/75431