Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:11072
HistoryJan 15, 2019 - 8:56 a.m.

Man-in-the-Middle (MitM)

2019-01-1508:56:39
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
6

0.001 Low

EPSS

Percentile

50.1%

Ruby is vulnerable to man-in-the-middle attack. The SSL client’s hostname identity check does not properly handle certificates with hostnames containing NULL bytes. A remote attacker, who has obtained a specific certificate that is signed by an trusted CA, is able to exploit the vulnerability to perform man-in-the-middle attacks or spoof SSL servers.

References