PT-2023-9883 · Ruby · Jruby-Openssl

Nahi

+1

·

Published

2023-01-19

·

Updated

2023-12-14

·

CVE-2009-4123

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions jruby-openssl gem versions prior to 0.6
Description A security issue was found in the handling of SSL certificate validation, where failed verification did not properly alert the application, making it vulnerable to attacks. This could allow attackers to make a client believe a connection to a rogue SSL server is legitimate or to penetrate client-validated SSL server applications using a dummy certificate.
Recommendations For versions prior to 0.6, update the jruby-openssl gem to version 0.6 or later to resolve the issue. As a temporary workaround, consider disabling SSL connections until the update is applied. Restrict access to sensitive applications using the jruby-openssl gem to minimize the risk of exploitation.

Exploit

Fix

Improper Certificate Validation

Weakness Enumeration

Related Identifiers

CVE-2009-4123
GHSA-XGV7-PQQH-H2W9

Affected Products

Jruby-Openssl