CVE-2019-7615: Elastic APM-Agent-Ruby
High severity, CVSS 7.4. EPSS: 0.6% chance of exploitation in the next 30 days.
A TLS certificate validation flaw was found in Elastic APM agent for Ruby versions before 2.9.0. When specifying a trusted server CA certificate via the 'server_ca_cert' setting, the Ruby agent would not properly verify the certificate returned by the APM server. This could result in a man in the middle style attack against the Ruby agent.
Affected products
- Elastic APM-Agent-Ruby: before 2.9.0 (fixed in 2.9.0)
Published 2019-07-30. Last modified 2026-06-17.