{"id":"GHSA-6wpv-cj6x-v3jw","summary":"http vulnerable to Exposure of Sensitive Information to an Unauthorized Actor","details":"The Ruby http gem before 0.6.4 and 0.7.3 does not verify hostnames in SSL connections, which might allow remote attackers to obtain sensitive information via a man-in-the-middle-attack.","aliases":["CVE-2015-1828"],"modified":"2026-04-17T19:17:40.383394Z","published":"2018-03-13T16:15:57Z","database_specific":{"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2020-06-16T21:20:24Z","nvd_published_at":"2017-10-06T22:29:00Z","cwe_ids":["CWE-200"]},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2015-1828"},{"type":"WEB","url":"https://github.com/ruby/openssl/issues/8"},{"type":"PACKAGE","url":"https://github.com/httprb/http"},{"type":"WEB","url":"https://github.com/rubysec/ruby-advisory-db/blob/master/gems/http/CVE-2015-1828.yml"},{"type":"WEB","url":"https://groups.google.com/forum/#!topic/httprb/jkb4oxwZjkU"},{"type":"WEB","url":"https://my.diffend.io/gems/http/0.6.3/0.6.4"},{"type":"WEB","url":"https://my.diffend.io/gems/http/0.7.2/0.7.3"},{"type":"WEB","url":"https://rubysec.com/advisories/http-CVE-2015-1828"}],"affected":[{"package":{"name":"http","ecosystem":"RubyGems","purl":"pkg:gem/http"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0.7.0"},{"fixed":"0.7.3"}]}],"versions":["0.7.0","0.7.1","0.7.2"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2018/03/GHSA-6wpv-cj6x-v3jw/GHSA-6wpv-cj6x-v3jw.json"}},{"package":{"name":"http","ecosystem":"RubyGems","purl":"pkg:gem/http"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.6.4"}]}],"versions":["0.0.0","0.0.1","0.0.2","0.1.0","0.2.0","0.3.0","0.4.0","0.5.0","0.5.0.pre","0.5.0.pre2","0.5.1","0.6.0","0.6.0.pre","0.6.1","0.6.2","0.6.3"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2018/03/GHSA-6wpv-cj6x-v3jw/GHSA-6wpv-cj6x-v3jw.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"}]}