{"id":"CVE-2009-4123","aliases":[],"url":"https://o3.security/vulnerability/CVE-2009-4123","summary":"jruby-openssl gem for JRuby fails to do proper certificate validation","details":"A security problem involving peer certificate verification was found where failed verification silently did nothing, making affected applications vulnerable to attackers. Attackers could lead a client application to believe that a secure connection to a rogue SSL server is legitimate. Attackers could also penetrate client-validated SSL server applications with a dummy certificate.\n","published":"2023-01-19T17:51:27Z","modified":"2024-02-16T08:07:53.674871Z","cvss":{"score":7.5,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"RubyGems","name":"jruby-openssl","fixedVersion":"0.6"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2009-4123"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-xgv7-pqqh-h2w9"},{"type":"WEB","url":"https://github.com/jruby/jruby-openssl"},{"type":"WEB","url":"https://github.com/rubysec/ruby-advisory-db/blob/master/gems/jruby-openssl/CVE-2009-4123.yml"},{"type":"WEB","url":"https://web.archive.org/web/20101213091125/http://jruby.org/2009/12/07/vulnerability-in-jruby-openssl"},{"type":"WEB","url":"http://jruby.org/2009/12/07/vulnerability-in-jruby-openssl"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2024-02-16T08:07:53.674871Z"}}