CVE Database
/

CVE-2019-7615

Back to search

CVE-2019-7615

Published: Jul 30, 2019

Modified: Aug 4, 2024

PUBLISHED

Description

A TLS certificate validation flaw was found in Elastic APM agent for Ruby versions before 2.9.0. When specifying a trusted server CA certificate via the 'server_ca_cert' setting, the Ruby agent would not properly verify the certificate returned by the APM server. This could result in a man in the middle style attack against the Ruby agent.

VendorProductVersions

Elastic

Elastic APM agent for Ruby

affected
before 2.9.0

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now