Sha256: d4885ec8283da1634ea8d0470c2542cb12f1375c1f8fc8514a1e88144d0b45d0
Contents?: true
Size: 684 Bytes
Versions: 1
Compression:
Stored size: 684 Bytes
Contents
--- gem: rbovirt cve: 2014-0036 osvdb: 104080 url: https://nvd.nist.gov/vuln/detail/CVE-2014-0036 title: rbovirt Gem for Ruby contains a flaw date: 2014-03-05 description: | rbovirt Gem for Ruby contains a flaw related to certificate validation. The issue is due to the program failing to validate SSL certificates. This may allow an attacker with access to network traffic (e.g. MiTM, DNS cache poisoning) to spoof the SSL server via an arbitrary certificate that appears valid. Such an attack would allow for the interception of sensitive traffic, and potentially allow for the injection of content into the SSL stream. cvss_v2: 6.8 patched_versions: - '>= 0.0.24'
Version data entries
1 entries across 1 versions & 1 rubygems
Version | Path |
---|---|
bundler-audit-0.7.0.1 | data/ruby-advisory-db/gems/rbovirt/CVE-2014-0036.yml |