EM-HTTP-Request 1.1.5 uses the library eventmachine in an insecure way that allows an attacker to perform a man-in-the-middle attack against users of the library. The hostname in a TLS server certificate is not verified.
Metrics
Affected Vendors & Products
Advisories
Source | ID | Title |
---|---|---|
![]() |
EUVD-2021-1157 | EM-HTTP-Request 1.1.5 uses the library eventmachine in an insecure way that allows an attacker to perform a man-in-the-middle attack against users of the library. The hostname in a TLS server certificate is not verified. |
![]() |
GHSA-q27f-v3r6-9v77 | Improper Certificate Validation in EM-HTTP-Request |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.

Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-04T12:18:18.262Z
Reserved: 2020-05-25T00:00:00
Link: CVE-2020-13482

No data.

Status : Modified
Published: 2020-05-25T22:15:09.860
Modified: 2024-11-21T05:01:21.413
Link: CVE-2020-13482


No data.