VDB
Sign up
HIGH7.5

GHSA-xgv7-pqqh-h2w9

jruby-openssl gem for JRuby fails to do proper certificate validation

Quick fix

GHSA-xgv7-pqqh-h2w9 — jruby-openssl: upgrade to the fixed version with the command below.

bundle update jruby-openssl

Details

A security problem involving peer certificate verification was found where failed verification silently did nothing, making affected applications vulnerable to attackers. Attackers could lead a client application to believe that a secure connection to a rogue SSL server is legitimate. Attackers could also penetrate client-validated SSL server applications with a dummy certificate.

Are you affected?

Enter the version of the package you're using.

Affected packages

RubyGems/jruby-openssl
Introduced in: 0Fixed in: 0.6
Fixbundle update jruby-openssl

References