The rbovirt gem before 0.0.24 for Ruby uses the rest-client gem with SSL verification disabled, which allows remote attackers to conduct man-in-the-middle attacks via unspecified vectors.
{
"cwe_ids": [],
"github_reviewed": true,
"github_reviewed_at": "2020-06-16T22:01:20Z",
"nvd_published_at": "2014-04-17T14:55:06Z",
"severity": "MODERATE"
}