Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2016-11086

Опубликовано: 24 сент. 2020
Источник: debian
EPSS Низкий

Описание

lib/oauth/consumer.rb in the oauth-ruby gem through 0.5.4 for Ruby does not verify server X.509 certificates if a certificate bundle cannot be found, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
ruby-oauthfixed0.5.6-1experimentalpackage
ruby-oauthunfixedpackage

Примечания

  • https://github.com/oauth-xx/oauth-ruby/issues/137

  • Likely minor issue since the package that exist is generated by ca-certificates

  • package and ca-certificates in the package dependency list. Hence even though the

  • package is vulnerable the problem do not exist in Debian unless the admin has

  • explicitly removed the file from the filesystem.

  • Fixing this vulnerability can cause a regression in the case the

  • admin has intentionally removed this file to not check certificates.

EPSS

Процентиль: 30%
0.00112
Низкий

Связанные уязвимости

CVSS3: 7.4
ubuntu
больше 5 лет назад

lib/oauth/consumer.rb in the oauth-ruby gem through 0.5.4 for Ruby does not verify server X.509 certificates if a certificate bundle cannot be found, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information.

CVSS3: 7.4
nvd
больше 5 лет назад

lib/oauth/consumer.rb in the oauth-ruby gem through 0.5.4 for Ruby does not verify server X.509 certificates if a certificate bundle cannot be found, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information.

CVSS3: 7.4
github
почти 5 лет назад

Improper Certificate Validation in oauth ruby gem

EPSS

Процентиль: 30%
0.00112
Низкий