CVE-2019-7615: Elastic APM-Agent-Ruby

High severity, CVSS 7.4. EPSS: 0.6% chance of exploitation in the next 30 days.

A TLS certificate validation flaw was found in Elastic APM agent for Ruby versions before 2.9.0. When specifying a trusted server CA certificate via the 'server_ca_cert' setting, the Ruby agent would not properly verify the certificate returned by the APM server. This could result in a man in the middle style attack against the Ruby agent.

Affected products

  • Elastic APM-Agent-Ruby: before 2.9.0 (fixed in 2.9.0)

Published 2019-07-30. Last modified 2026-06-17.