{"id":"GHSA-p6p8-q4pj-f74m","summary":"Improper Certificate Validation in twitter-stream","details":"In voloko twitter-stream 0.1.16, missing TLS hostname validation allows an attacker to perform a man-in-the-middle attack against users of the library (because eventmachine is misused).","aliases":["CVE-2020-24392"],"modified":"2023-11-08T04:03:07.143996Z","published":"2021-03-29T16:28:42Z","database_specific":{"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2021-03-19T19:21:49Z","nvd_published_at":"2021-02-19T23:15:00Z","cwe_ids":["CWE-295"]},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2020-24392"},{"type":"WEB","url":"https://github.com/voloko/twitter-stream"},{"type":"ADVISORY","url":"https://securitylab.github.com/advisories/GHSL-2020-097-voloko-twitter-stream"}],"affected":[{"package":{"name":"twitter-stream","ecosystem":"RubyGems","purl":"pkg:gem/twitter-stream"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"0.1.16"}]}],"versions":["0.1.0","0.1.1","0.1.10","0.1.11","0.1.12","0.1.13","0.1.14","0.1.15","0.1.16","0.1.2","0.1.3","0.1.4","0.1.6","0.1.7","0.1.8","0.1.9"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/03/GHSA-p6p8-q4pj-f74m/GHSA-p6p8-q4pj-f74m.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N"}]}