Описание
Improper Certificate Validation in TweetStream
TweetStream 2.6.1 uses the library eventmachine in an insecure way that does not have TLS hostname validation. This allows an attacker to perform a man-in-the-middle attack.
Пакеты
Наименование
tweetstream
rubygems
Затронутые версииВерсия исправления
<= 2.6.1
Отсутствует
Связанные уязвимости
CVSS3: 5.9
nvd
почти 5 лет назад
TweetStream 2.6.1 uses the library eventmachine in an insecure way that does not have TLS hostname validation. This allows an attacker to perform a man-in-the-middle attack.