CVE-2015-1828

The Ruby http gem before 0.7.3 does not verify hostnames in SSL connections, which might allow remote attackers to obtain sensitive information via a man-in-the-middle-attack.
Configurations

Configuration 1 (hide)

cpe:2.3:a:http.rb_project:http.rb:*:*:*:*:*:ruby:*:*

History

07 Nov 2023, 02:24

Type Values Removed Values Added
References
  • {'url': 'https://groups.google.com/forum/#!topic/httprb/jkb4oxwZjkU', 'name': 'https://groups.google.com/forum/#!topic/httprb/jkb4oxwZjkU', 'tags': ['Third Party Advisory'], 'refsource': 'CONFIRM'}
  • () https://groups.google.com/forum/#%21topic/httprb/jkb4oxwZjkU -

Information

Published : 2017-10-06 22:29

Updated : 2023-11-07 02:24


NVD link : CVE-2015-1828

Mitre link : CVE-2015-1828


JSON object : View

Products Affected

http.rb_project

  • http.rb
CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor