Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2020-24392

Опубликовано: 19 фев. 2021
Источник: debian
EPSS Низкий

Описание

In voloko twitter-stream 0.1.10, missing TLS hostname validation allows an attacker to perform a man-in-the-middle attack against users of the library (because eventmachine is misused).

Пакеты

ПакетСтатусВерсия исправленияРелизТип
ruby-twitter-streamremovedpackage
ruby-twitter-streamignoredbookwormpackage
ruby-twitter-streamno-dsabullseyepackage
ruby-twitter-streamno-dsabusterpackage
ruby-twitter-streamno-dsastretchpackage

Примечания

  • https://securitylab.github.com/advisories/GHSL-2020-097-voloko-twitter-stream

EPSS

Процентиль: 40%
0.00185
Низкий

Связанные уязвимости

CVSS3: 5.9
ubuntu
почти 5 лет назад

In voloko twitter-stream 0.1.10, missing TLS hostname validation allows an attacker to perform a man-in-the-middle attack against users of the library (because eventmachine is misused).

CVSS3: 5.9
nvd
почти 5 лет назад

In voloko twitter-stream 0.1.10, missing TLS hostname validation allows an attacker to perform a man-in-the-middle attack against users of the library (because eventmachine is misused).

CVSS3: 5.9
github
почти 5 лет назад

Improper Certificate Validation in twitter-stream

EPSS

Процентиль: 40%
0.00185
Низкий