Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2015-1828

Опубликовано: 06 окт. 2017
Источник: debian

Описание

The Ruby http gem before 0.7.3 does not verify hostnames in SSL connections, which might allow remote attackers to obtain sensitive information via a man-in-the-middle-attack.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
ruby-httpfixed1.0.2-2package
ruby-httpno-dsajessiepackage

Примечания

  • http.rb failed to call the `#post_connection_check` method on SSL connections.

  • This method implements hostname verification, and without it `http.rb` was

  • vulnerable to MitM attacks. The problem was corrected by calling

  • `#post_connection_check`.

  • Fixed by: https://github.com/httprb/http/commit/24626bfcdeda1084502575c3fbb6091c9e2815e0

Связанные уязвимости

CVSS3: 5.9
ubuntu
больше 8 лет назад

The Ruby http gem before 0.7.3 does not verify hostnames in SSL connections, which might allow remote attackers to obtain sensitive information via a man-in-the-middle-attack.

CVSS3: 5.9
nvd
больше 8 лет назад

The Ruby http gem before 0.7.3 does not verify hostnames in SSL connections, which might allow remote attackers to obtain sensitive information via a man-in-the-middle-attack.

CVSS3: 5.9
github
почти 8 лет назад

http vulnerable to Exposure of Sensitive Information to an Unauthorized Actor