The connect method in lib/net/http.rb in the (1) Net::HTTP and (2) Net::HTTPS libraries in Ruby 1.8.5 and 1.8.6 does not verify that the commonName (CN) field in a server certificate matches the domain name in an HTTPS request, which makes it easier for remote attackers to intercept SSL transmissions via a man-in-the-middle attack or spoofed web site.
CVSS Details
- CVSS 3.1 Base Score: 5.9
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Oracle_linux | — | Upgrade ruby-riUpgrade ruby-docsUpgrade ruby-modeUpgrade rubyUpgrade ruby-libsUpgrade ruby-irbUpgrade ruby-rdocUpgrade ruby-develUpgrade ruby-tcltk | Oct 16, 2024 | Oct 1, 2007 |
| Suse | — | Upgrade rubyUpgrade ruby-examplesUpgrade ruby-develUpgrade ruby-tkUpgrade ruby-test-suiteUpgrade ruby-doc-htmlUpgrade ruby-doc-ri | Feb 17, 2015 | Jul 9, 2013 |
| Ubuntu | — | Upgrade libopenssl-ruby1.8Upgrade libruby1.8 | Nov 8, 2024 | Oct 1, 2007 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub