CVE-2007-5162 describes a vulnerability in the Net::HTTP and Net::HTTPS libraries within Ruby versions 1.8.5 and 1.8.6. The flaw lies in the connect method, which fails to verify if the commonName (CN) field in a server's SSL certificate matches the requested domain name. This oversight facilitates man-in-the-middle attacks and website spoofing, allowing remote attackers to intercept SSL transmissions. The vulnerability has a CVSS score of 4.3 (Medium severity), indicating a network-based attack with medium complexity and potential for partial information disclosure (integrity impact). There is no evidence of active exploitation, nor are there publicly available exploit modules in Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage for this CVE are minimal, suggesting low public awareness and attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.8.5CPE matchmatch criteria | cpe:2.3:a:ruby-lang:ruby:1.8.5:*:*:*:*:*:*:* | ||
1.8.6CPE matchmatch criteria | cpe:2.3:a:ruby-lang:ruby:1.8.6:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:N/I:P/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.