verify_certificate_identity in the OpenSSL extension in Ruby before 2.0.0 patchlevel 645, 2.1.x before 2.1.6, and 2.2.x before 2.2.2 does not properly validate hostnames, which allows remote attackers to spoof servers via vectors related to (1) multiple wildcards, (1) wildcards in IDNA names, (3) case sensitivity, and (4) non-ASCII characters.
CVSS Details
- CVSS 3.1 Base Score: 5.9
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Apple Osx Ruby | — | Upgrade macOS to the latest version | Apr 5, 2017 | Apr 5, 2017 |
| Freebsd | — | Upgrade ruby20Upgrade ruby21Upgrade rubyUpgrade ruby22 | Dec 10, 2025 | Apr 14, 2015 |
| Oracle Solaris | — | Upgrade runtime/ruby-19 to version 1.9.3.551-0.175.2.13.0.4.0 on Solaris 11.2Upgrade runtime/ruby-18 to version 1.8.7.374-0.175.2.12.0.4.0 on Solaris 11.2 | May 29, 2017 | May 29, 2017 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Nov 29, 2019 |
| Suse | — | Upgrade ruby-tkUpgrade ruby-doc-htmlUpgrade ruby2.1Upgrade ruby2.1-develUpgrade libruby2_1-2_1Upgrade ruby-develUpgrade ruby-doc-riUpgrade ruby2.1-stdlibUpgrade ruby-test-suiteUpgrade ruby-examplesUpgrade ruby | Apr 5, 2017 | May 2, 2015 |
| Ubuntu | — | Upgrade libruby2.0Upgrade libruby2.3Upgrade ruby2.3Upgrade libruby1.9.1Upgrade ruby2.0Upgrade ruby1.9.1 | Jul 26, 2017 | May 2, 2015 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub