jruby-openssl gem for JRuby fails to do proper certificate validation
High severity
GitHub Reviewed
Published
Jan 19, 2023
to the GitHub Advisory Database
•
Updated Dec 14, 2023
Description
Published to the GitHub Advisory Database
Jan 19, 2023
Reviewed
Jan 19, 2023
Published by the National Vulnerability Database
Dec 12, 2023
Last updated
Dec 14, 2023
A security problem involving peer certificate verification was found where failed verification silently did nothing, making affected applications vulnerable to attackers. Attackers could lead a client application to believe that a secure connection to a rogue SSL server is legitimate. Attackers could also penetrate client-validated SSL server applications with a dummy certificate.
References