HTTP v0.7.3 Release Notes
Release Date: 2015-03-24 // about 9 years ago-
- SECURITY FIX: http.rb failed to call the
#post_connection_check
method on SSL connections. This method implements hostname verification, and without ithttp.rb
was vulnerable to MitM attacks. The problem was corrected by calling#post_connection_check
(CVE-2015-1828) ([@zanker])
- SECURITY FIX: http.rb failed to call the