Authentication Bypass Affecting jruby-openssl package, versions < 0.6


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.2% (43rd percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-RUBY-JRUBYOPENSSL-20007
  • published6 Dec 2009
  • disclosed6 Dec 2009
  • creditHiroshi Nakamura

Introduced: 6 Dec 2009

CVE-2009-4123  (opens in a new tab)
CWE-592  (opens in a new tab)

Overview

JRuby-OpenSSL is an add-on gem for JRuby that emulates the Ruby OpenSSL native library. A security problem involving peer certificate verification was found where failed verification silently did nothing, making affected applications vulnerable to attackers. Attackers could lead a client application to believe that a secure connection to a rogue SSL server is legitimate. Attackers could also penetrate client-validated SSL server applications with a dummy certificate.

CVSS Base Scores

version 3.1