Improper Certificate Validation in oauth ruby gem
High severity
GitHub Reviewed
Published
Apr 22, 2021
to the GitHub Advisory Database
•
Updated Jan 24, 2023
Description
Published by the National Vulnerability Database
Sep 24, 2020
Reviewed
Apr 20, 2021
Published to the GitHub Advisory Database
Apr 22, 2021
Last updated
Jan 24, 2023
lib/oauth/consumer.rb in the oauth-ruby gem through 0.5.4 for Ruby does not verify server X.509 certificates if a certificate bundle cannot be found, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information.
References