Skip to content
New issue

Have a question about this project? # for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “#”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? # to your account

[Security Bug] Insecure crypto usage #49

Open
nageshservicenow opened this issue Mar 20, 2024 · 0 comments
Open

[Security Bug] Insecure crypto usage #49

nageshservicenow opened this issue Mar 20, 2024 · 0 comments

Comments

@nageshservicenow
Copy link

Description

Detected SSL that will accept an unverified connection. This makes the connections susceptible to man-in-the-middle attacks.

Used below verify mode.
..
http.verify_mode = OpenSSL::SSL::VERIFY_NONE
..

Effected source files:

http.verify_mode = OpenSSL::SSL::VERIFY_NONE

http.verify_mode = OpenSSL::SSL::VERIFY_NONE

Remediation

  1. Use 'OpenSSL::SSL::VERIFY_PEER' instead.
# for free to join this conversation on GitHub. Already have an account? # to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant