CVE-2009-4123
Severity CVSS v4.0:
Pending analysis
Type:
CWE-295
Improper Certificate Validation
Publication date:
12/12/2023
Last modified:
21/11/2024
Description
The jruby-openssl gem before 0.6 for JRuby mishandles SSL certificate validation.
Impact
Base Score 3.x
7.50
Severity 3.x
HIGH
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:a:jruby:jruby-openssl:*:*:*:*:*:*:*:* | 0.6 (excluding) |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://jruby.org/2009/12/07/vulnerability-in-jruby-openssl
- https://github.com/advisories/GHSA-xgv7-pqqh-h2w9
- https://github.com/rubysec/ruby-advisory-db/blob/master/gems/jruby-openssl/CVE-2009-4123.yml
- https://web.archive.org/web/20101213091125/http://jruby.org/2009/12/07/vulnerability-in-jruby-openssl
- http://jruby.org/2009/12/07/vulnerability-in-jruby-openssl
- https://github.com/advisories/GHSA-xgv7-pqqh-h2w9
- https://github.com/rubysec/ruby-advisory-db/blob/master/gems/jruby-openssl/CVE-2009-4123.yml
- https://web.archive.org/web/20101213091125/http://jruby.org/2009/12/07/vulnerability-in-jruby-openssl