CVE-2015-1855
Severity
5.9MEDIUM
EPSS
2.7%
top 14.07%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedNov 29
Latest updateMay 24
Description
verify_certificate_identity in the OpenSSL extension in Ruby before 2.0.0 patchlevel 645, 2.1.x before 2.1.6, and 2.2.x before 2.2.2 does not properly validate hostnames, which allows remote attackers to spoof servers via vectors related to (1) multiple wildcards, (1) wildcards in IDNA names, (3) case sensitivity, and (4) non-ASCII characters.
CVSS vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:NExploitability: 2.2 | Impact: 3.6
Affected Packages8 packages
Also affects: Debian Linux 7.0, 8.0, 9.0
🔴Vulnerability Details
4GHSA▶
GHSA-4x8v-74xf-h4g3: verify_certificate_identity in the OpenSSL extension in Ruby before 2↗2022-05-24
CVEList
▶