Back

HIGH

rubygem-em-http-request: missing SSL hostname validation allows MITM

Published May 25, 2020

Description

EM-HTTP-Request 1.1.5 uses the library eventmachine in an insecure way that allows an attacker to perform a man-in-the-middle attack against users of the library. The hostname in a TLS server certificate is not verified.

Affected products

Remediation

Red Hat mitigation

Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update as soon as possible.

Metrics

References (13)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published May 25, 2020
Updated Aug 4, 2024
Reserved May 25, 2020
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Important
Public date May 24, 2020
GHSA-Q27F-V3R6-9V77