{"id":"UBUNTU-CVE-2020-15133","details":"In faye-websocket before version 0.11.0, there is a lack of certification validation in TLS handshakes. The `Faye::WebSocket::Client` class uses the `EM::Connection#start_tls` method in EventMachine to implement the TLS handshake whenever a `wss:` URL is used for the connection. This method does not implement certificate verification by default, meaning that it does not check that the server presents a valid and trusted TLS certificate for the expected hostname. That means that any `wss:` connection made using this library is vulnerable to a man-in-the-middle attack, since it does not confirm the identity of the server it is connected to. For further background information on this issue, please see the referenced GitHub Advisory. Upgrading `faye-websocket` to v0.11.0 is recommended.","modified":"2026-05-20T16:04:10.849458088Z","published":"2020-07-31T18:15:00Z","upstream":["CVE-2020-15133"],"references":[{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2020-15133"},{"type":"REPORT","url":"https://github.com/faye/faye-websocket-ruby/security/advisories/GHSA-2v5c-755p-p4gv"},{"type":"REPORT","url":"https://github.com/faye/faye-websocket-ruby/pull/129"},{"type":"REPORT","url":"https://blog.jcoglan.com/2020/07/31/missing-tls-verification-in-faye/"},{"type":"REPORT","url":"https://www.cve.org/CVERecord?id=CVE-2020-15133"}],"affected":[{"package":{"name":"ruby-faye-websocket","ecosystem":"Ubuntu:20.04:LTS","purl":"pkg:deb/ubuntu/ruby-faye-websocket?arch=source&distro=focal"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["0.10.7-1"],"ecosystem_specific":{"binaries":[{"binary_version":"0.10.7-1","binary_name":"ruby-faye-websocket"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2020/UBUNTU-CVE-2020-15133.json"}},{"package":{"name":"ruby-faye-websocket","ecosystem":"Ubuntu:22.04:LTS","purl":"pkg:deb/ubuntu/ruby-faye-websocket?arch=source&distro=jammy"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["0.11.0-1"],"ecosystem_specific":{"binaries":[{"binary_name":"ruby-faye-websocket","binary_version":"0.11.0-1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2020/UBUNTU-CVE-2020-15133.json"}},{"package":{"name":"ruby-faye-websocket","ecosystem":"Ubuntu:24.04:LTS","purl":"pkg:deb/ubuntu/ruby-faye-websocket?arch=source&distro=noble"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["0.11.0-1"],"ecosystem_specific":{"binaries":[{"binary_version":"0.11.0-1","binary_name":"ruby-faye-websocket"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2020/UBUNTU-CVE-2020-15133.json"}},{"package":{"name":"ruby-faye-websocket","ecosystem":"Ubuntu:25.10","purl":"pkg:deb/ubuntu/ruby-faye-websocket?arch=source&distro=questing"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["0.11.0-1"],"ecosystem_specific":{"binaries":[{"binary_version":"0.11.0-1","binary_name":"ruby-faye-websocket"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2020/UBUNTU-CVE-2020-15133.json"}},{"package":{"name":"ruby-faye-websocket","ecosystem":"Ubuntu:26.04:LTS","purl":"pkg:deb/ubuntu/ruby-faye-websocket?arch=source&distro=resolute"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["0.11.0-1"],"ecosystem_specific":{"binaries":[{"binary_version":"0.11.0-1","binary_name":"ruby-faye-websocket"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2020/UBUNTU-CVE-2020-15133.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:N"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N"},{"type":"Ubuntu","score":"medium"}]}