VYPR
Unrated severityNVD Advisory· Published Oct 1, 2007· Updated Apr 23, 2026

CVE-2007-5162

CVE-2007-5162

Description

The connect method in lib/net/http.rb in the (1) Net::HTTP and (2) Net::HTTPS libraries in Ruby 1.8.5 and 1.8.6 does not verify that the commonName (CN) field in a server certificate matches the domain name in an HTTPS request, which makes it easier for remote attackers to intercept SSL transmissions via a man-in-the-middle attack or spoofed web site.

Affected products

2
  • Ruby Lang/Ruby2 versions
    cpe:2.3:a:ruby-lang:ruby:1.8.5:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:ruby-lang:ruby:1.8.5:*:*:*:*:*:*:*
    • cpe:2.3:a:ruby-lang:ruby:1.8.6:*:*:*:*:*:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

35

News mentions

0

No linked articles in our index yet.