CVE Published: 30/07/2019 |
CVE Updated: 04/08/2024 |
CVE Year: 2019 Source: elastic |
Vendor: Elastic |
Product: Elastic APM agent for Ruby Status : PUBLISHED
CVE-2019-7615 Description
A TLS certificate validation flaw was found in Elastic APM agent for Ruby versions before 2.9.0. When specifying a trusted server CA certificate via the \'server_ca_cert\' setting, the Ruby agent would not properly verify the certificate returned by the APM server. This could result in a man in the middle style attack against the Ruby agent.