CVE-2020-13482
published 2020-05-25CVE-2020-13482: EM-HTTP-Request 1.1.5 uses the library eventmachine in an insecure way that allows an attacker to perform a man-in-the-middle attack against users of the…
PriorityP336high7.4CVSS 3.1
AVNACHPRNUINSUCHIHAN
EPSS
0.91%
56.3th percentile
EM-HTTP-Request 1.1.5 uses the library eventmachine in an insecure way that allows an attacker to perform a man-in-the-middle attack against users of the library. The hostname in a TLS server certificate is not verified.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| em-http-request_project | em-http-request | — | — |
| em-http-request_project | em-http-request | >= 0 < 1.1.6 | 1.1.6 |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
CVSS provenance
nvdv3.17.4HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
nvdv2.05.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:N
vendor_redhat7.4HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Improper Certificate Validation in EM-HTTP-Request
ghsa·2021-05-24
CVE-2020-13482 [HIGH] CWE-295 Improper Certificate Validation in EM-HTTP-Request
Improper Certificate Validation in EM-HTTP-Request
EM-HTTP-Request 1.1.5 uses the library eventmachine in an insecure way that allows an attacker to perform a man-in-the-middle attack against users of the library. The hostname in a TLS server certificate is not verified.
OSV
Improper Certificate Validation in EM-HTTP-Request
osv·2021-05-24
CVE-2020-13482 [HIGH] Improper Certificate Validation in EM-HTTP-Request
Improper Certificate Validation in EM-HTTP-Request
EM-HTTP-Request 1.1.5 uses the library eventmachine in an insecure way that allows an attacker to perform a man-in-the-middle attack against users of the library. The hostname in a TLS server certificate is not verified.
Red Hat
rubygem-em-http-request: missing SSL hostname validation allows MITM
vendor_redhat·2020-05-24·CVSS 7.4
CVE-2020-13482 [HIGH] CWE-297 rubygem-em-http-request: missing SSL hostname validation allows MITM
rubygem-em-http-request: missing SSL hostname validation allows MITM
EM-HTTP-Request 1.1.5 uses the library eventmachine in an insecure way that allows an attacker to perform a man-in-the-middle attack against users of the library. The hostname in a TLS server certificate is not verified.
A flaw was found in rubygem-em-http-request. The eventmachine library does not verify the hostname in a TLS server certificate which can allow an attacker to perform a man-in-the-middle attack. The highest threat from this vulnerability is to data confidentiality and integrity.
Mitigation: Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update as soon as possible.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/igrigorik/em-http-request/issues/339https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MKYP5TR5NTVVDX5R4HCNNH2OQR7M4X3J/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Z32PUJA6RGBZ3TKSOTGUXZ45662S3MVF/https://securitylab.github.com/advisories/GHSL-2020-094-igrigorik-em-http-requesthttps://github.com/igrigorik/em-http-request/issues/339https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MKYP5TR5NTVVDX5R4HCNNH2OQR7M4X3J/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Z32PUJA6RGBZ3TKSOTGUXZ45662S3MVF/https://securitylab.github.com/advisories/GHSL-2020-094-igrigorik-em-http-request
2020-05-25
Published