Impact
The gist RubyGem prior to version 6.1.0 mistakenly sets the SSL certificate verification mode to VERIFY_NONE, allowing an attacker on the network path to substitute any TLS certificate. This malicious certificate can be used to intercept, read, or modify HTTPS traffic to the GitHub API, enabling the theft of OAuth tokens and login credentials and the alteration of the victim’s gists. The vulnerability is a classic example of improper certificate validation, classified as CWE‑295, and results in a severe breach of confidentiality, integrity, and potentially availability.
Affected Systems
All installations of the defunkt:gist RubyGem older than 6.1.0 are affected, including source versions such as 6.0.0. Users must check the gem version in their applications or development environments and verify whether it falls under this scope.
Risk and Exploitability
With a CVSS score of 9.1, the vulnerability is considered Critical. The EPSS score is not available, but the lack of a CISA KEV listing does not diminish the inherent danger; an on‑path attacker can exploit the flaw without additional prerequisites. The affected code path is exposed whenever HTTP requests are made to GitHub via the gem, so any application that relies on the gem is at risk. The primary attack vector is a network‑level attacker in the traffic path, able to present an arbitrary certificate and intercept traffic. This poses an immediate threat to users who authenticate via GitHub API calls that could be replayed or tampered with.
OpenCVE Enrichment