CVE-2015-1828

The Ruby http gem before 0.7.3 does not verify hostnames in SSL connections, which might allow remote attackers to obtain sensitive information via a man-in-the-middle-attack.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:http.rb_project:http.rb:*:*:*:*:*:ruby:*:*

Information

Published : 2017-10-06 22:29

Updated : 2019-10-17 12:58


NVD link : CVE-2015-1828

Mitre link : CVE-2015-1828


JSON object : View

Products Affected

http.rb_project

  • http.rb
CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor