PT-2023-9883 · Ruby · Jruby-Openssl
Nahi
+1
·
Published
2023-01-19
·
Updated
2023-12-14
·
CVE-2009-4123
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
jruby-openssl gem versions prior to 0.6
Description
A security issue was found in the handling of SSL certificate validation, where failed verification did not properly alert the application, making it vulnerable to attacks. This could allow attackers to make a client believe a connection to a rogue SSL server is legitimate or to penetrate client-validated SSL server applications using a dummy certificate.
Recommendations
For versions prior to 0.6, update the jruby-openssl gem to version 0.6 or later to resolve the issue. As a temporary workaround, consider disabling SSL connections until the update is applied. Restrict access to sensitive applications using the jruby-openssl gem to minimize the risk of exploitation.
Exploit
Fix
Improper Certificate Validation
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Jruby-Openssl