Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
A TLS certificate validation flaw was found in Elastic APM agent for Ruby versions before 2.9.0. When specifying a trusted server CA certificate via the 'server_ca_cert' setting, the Ruby agent would not properly verify the certificate returned by the APM server. This could result in a man in the middle style attack against the Ruby agent.
CVSS Information
N/A
Vulnerability Type
证书验证不恰当
Vulnerability Title
Elasticsearch Elastic APM agent for Ruby 信任管理问题漏洞
Vulnerability Description
Elasticsearch Elastic APM agent for Ruby是荷兰Elasticsearch公司的一款基于Ruby的Elastic APM(应用程序性能监控)代理程序。 Elastic APM agent for Ruby 2.9.0之前版本中存在安全漏洞,该漏洞源于程序没有正确验证由APM服务器返回的凭证。攻击者可利用该漏洞实施中间人攻击。
CVSS Information
N/A
Vulnerability Type
N/A