I'm running a security scanner against an app I'm developing and it's rising red alert, maximum security thread for the gem rotr which uses in its Gemfile source with HTTP protocol revealing a possibility for man in the middle attack that potentially can allow an attacker to inject any code into an application
The link to Gemfile in question - https://github.com/mdp/rotp/blob/master/Gemfile
It states:
source 'http://rubygems.org'
Is it real issue if this gem listed as a dependency and in my Gemfile I'm using:
source 'https://rubygems.org'
I tried to find out how exactly it's working but wasn't able to.
I.e. which way bundler is working:
It pulls all gems I specify from https://rubygems.org, then it pull all dependencies separately for each gem, from the source specified in each Gemfile (for each gem) and in case of ropt gem it pulls from http://rubygems.org (NOT https) - thus opening theoretical possibility for man in the middle attack while installing ropt gem
Bundler pulls all gem from the source specified in MY Gemfile (https://rubygems.org) so even if a Gem specifies http://rubygems.org (NOT https) - it'll be pulled through the secure protocol from the location I specify so there is no theoretical possibility for man in the middle attack