CVE-2015-1855
verify_certificate_identity in the OpenSSL extension in Ruby before 2.0.0 patchlevel 645, 2.1.x before 2.1.6, and 2.2.x before 2.2.2 does not properly validate hostnames, which allows remote attackers to spoof servers via vectors related to (1) multiple…
Does this matter?
Lower severity and a low EPSS score (2.81%). Track it; it rarely justifies an emergency change on its own.
Description
verify_certificate_identity in the OpenSSL extension in Ruby before 2.0.0 patchlevel 645, 2.1.x before 2.1.6, and 2.2.x before 2.2.2 does not properly validate hostnames, which allows remote attackers to spoof servers via vectors related to (1) multiple wildcards, (1) wildcards in IDNA names, (3) case sensitivity, and (4) non-ASCII characters.
- CVSS 3.1
- 5.9 MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
- EPSS
- 2.81% probability · 86th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20
- Affected
- ruby-lang/ruby · ruby-lang/trunk · debian/debian linux · puppet/puppet agent · puppet/puppet enterprise
- Source
- secalert@redhat.com
References
- http://www.debian.org/security/2015/dsa-3245Third Party Advisory
- http://www.debian.org/security/2015/dsa-3246Third Party Advisory
- http://www.debian.org/security/2015/dsa-3247Third Party Advisory
- https://bugs.ruby-lang.org/issues/9644Third Party Advisory
- https://puppetlabs.com/security/cve/cve-2015-1855Third Party Advisory
- https://www.ruby-lang.org/en/news/2015/04/13/ruby-openssl-hostname-matching-vulnerability/Vendor Advisory
- http://www.debian.org/security/2015/dsa-3245Third Party Advisory
- http://www.debian.org/security/2015/dsa-3246Third Party Advisory
- http://www.debian.org/security/2015/dsa-3247Third Party Advisory
- https://bugs.ruby-lang.org/issues/9644Third Party Advisory
- https://puppetlabs.com/security/cve/cve-2015-1855Third Party Advisory
- https://www.ruby-lang.org/en/news/2015/04/13/ruby-openssl-hostname-matching-vulnerability/Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.