Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:31167
HistoryJul 10, 2021 - 2:45 p.m.

Man In The Middle (MitM)

2021-07-1014:45:44
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
24
ruby2.7
vulnerability
starttls stripping
network position
registry

EPSS

0.002

Percentile

64.4%

ruby2.7 is vulnerable to Man In the Middle Attack. An attacker may bypass the TLS protections by leveraging a network position between the client and the registry to block the StartTLS command, aka a “StartTLS stripping attack.”