脆弱性情報
高度な大規模言語モデル技術を使用していますが、出力には不正確または古い情報が含まれる可能性があります。Shenlongはデータの正確性を確保するよう努めていますが、実際の状況に基づいて検証・判断してください。
脆弱性タイトル
N/A
脆弱性説明
A TLS certificate validation flaw was found in Elastic APM agent for Ruby versions before 2.9.0. When specifying a trusted server CA certificate via the 'server_ca_cert' setting, the Ruby agent would not properly verify the certificate returned by the APM server. This could result in a man in the middle style attack against the Ruby agent.
CVSS情報
N/A
脆弱性タイプ
证书验证不恰当
脆弱性タイトル
Elasticsearch Elastic APM agent for Ruby 信任管理问题漏洞
脆弱性説明
Elasticsearch Elastic APM agent for Ruby是荷兰Elasticsearch公司的一款基于Ruby的Elastic APM(应用程序性能监控)代理程序。 Elastic APM agent for Ruby 2.9.0之前版本中存在安全漏洞,该漏洞源于程序没有正确验证由APM服务器返回的凭证。攻击者可利用该漏洞实施中间人攻击。
CVSS情報
N/A
脆弱性タイプ
N/A