CVE-2015-1828: MitM vulnerability
(updated )
The file http.rb
of the http package fails to call the OpenSSL::SSL::SSLSocket#post_connection_check
method to perform hostname verification. Because of this, an attacker with a valid certificate but with a mismatched subject can perform a Man-in-the-Middle attack.
References
Detect and mitigate CVE-2015-1828 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →