VDB
Sign up
HIGH7.4

GHSA-7359-3c6r-hfc2

Improper Certificate Validation in oauth ruby gem

Quick fix

GHSA-7359-3c6r-hfc2 — oauth: upgrade to the fixed version with the command below.

bundle update oauth

Details

lib/oauth/consumer.rb in the oauth-ruby gem through 0.5.4 for Ruby does not verify server X.509 certificates if a certificate bundle cannot be found, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information.

Are you affected?

Enter the version of the package you're using.

Affected packages

RubyGems/oauth
Introduced in: 0Fixed in: 0.5.5
Fixbundle update oauth

References