CVE-2017-0902 | RubyGems up to 2.6.12 GEM Install DNS access control (RHSA-2017:3485 / Nessus ID 102964)
A vulnerability classified as critical was found in RubyGems up to 2.6.12. Affected is an unknown function of the component GEM Install. The manipulation results in improper access controls (DNS).
This vulnerability is known as CVE-2017-0902. It is possible to launch the attack remotely. No exploit is available.
Upgrading the affected component is advised.