Product
The gist RubyGem versions prior to 6.1.0 contain an improper certificate validation vulnerability that allows on-path attackers to intercept and modify GitHub API traffic by exploiting the hardcoded use of OpenSSL::SSL::VERIFY_NONE.