Vulnerability Database

289,599

Total vulnerabilities in the database

CVE-2007-5162

The connect method in lib/net/http.rb in the (1) Net::HTTP and (2) Net::HTTPS libraries in Ruby 1.8.5 and 1.8.6 does not verify that the commonName (CN) field in a server certificate matches the domain name in an HTTPS request, which makes it easier for remote attackers to intercept SSL transmissions via a man-in-the-middle attack or spoofed web site.

  • Published: Oct 1, 2007
  • Updated: Apr 13, 2023
  • CVE: CVE-2007-5162
  • Severity: Low
  • Exploit:

CVSS v2:

  • Severity: Low
  • Score: 4.3
  • AV:N/AC:M/Au:N/C:N/I:P/A:N
Software From Fixed in
ruby-lang / ruby 1.8.5 1.8.5.x
ruby-lang / ruby 1.8.6 1.8.6.x