GHSA-35j2-p8fh-x966
Dashboard / Vulnerabilities / GHSA-35j2-p8fh-x966
Summary: Elastic APM agent for Ruby vulnerable to Improper Certificate Validation
Details: A TLS certificate validation flaw was found in Elastic APM agent for Ruby versions before 2.9.0. When specifying a trusted server CA certificate via the `server_ca_cert` setting, the Ruby agent would not properly verify the certificate returned by the APM server. This could result in a man in the middle style attack against the Ruby agent.
References: https://nvd.nist.gov/vuln/detail/CVE-2019-7615, https://github.com/elastic/apm-agent-ruby/pull/449, https://github.com/elastic/apm-agent-ruby, https://github.com/rubysec/ruby-advisory-db/blob/master/gems/elastic-apm/CVE-2019-7615.yml, https://www.elastic.co/community/security
Affected packages
Package
Name: elastic-apm
Purl: pkg:gem/elastic-apm
Affected ranges
Type: ECOSYSTEM
Events:
