HIGH7.4
GHSA-7359-3c6r-hfc2
Improper Certificate Validation in oauth ruby gem
Quick fix
GHSA-7359-3c6r-hfc2 — oauth: upgrade to the fixed version with the command below.
bundle update oauthDetails
lib/oauth/consumer.rb in the oauth-ruby gem through 0.5.4 for Ruby does not verify server X.509 certificates if a certificate bundle cannot be found, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2016-11086[ADVISORY]
- https://github.com/oauth-xx/oauth-ruby/issues/137[WEB]
- https://github.com/oauth-xx/oauth-ruby/commit/eb5b00a91d4ef0899082fdba929c34ccad6d4ccb[WEB]
- https://github.com/oauth-xx/oauth-ruby[PACKAGE]
- https://github.com/oauth-xx/oauth-ruby/releases/tag/v0.5.5[WEB]
- https://rubygems.org/gems/oauth[WEB]