516
VMScore

CVE-2016-11086

Published: 24/09/2020 Updated: 05/10/2020
CVSS v2 Base Score: 5.8 | Impact Score: 4.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 7.4 | Impact Score: 5.2 | Exploitability Score: 2.2
VMScore: 516
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:N

Vulnerability Summary

lib/oauth/consumer.rb in the oauth-ruby gem up to and including 0.5.4 for Ruby does not verify server X.509 certificates if a certificate bundle cannot be found, which allows man-in-the-middle malicious users to spoof servers and obtain sensitive information.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

oauth-ruby project oauth-ruby

Vendor Advisories

Debian Bug report logs - #970932 ruby-oauth: CVE-2016-11086 Package: src:ruby-oauth; Maintainer for src:ruby-oauth is Debian Ruby Extras Maintainers <pkg-ruby-extras-maintainers@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Fri, 25 Sep 2020 19:30:02 UTC Severity: important Tags ...