Lucene search

K
osvGoogleOSV:GHSA-6HRM-JQP3-64CV
HistoryApr 13, 2021 - 3:42 p.m.

Improper Certificate Validation in TweetStream

2021-04-1315:42:36
Google
osv.dev
8
tweetstream
certificate validation
eventmachine
tls
man-in-the-middle
attack
software

EPSS

0.001

Percentile

30.3%

TweetStream 2.6.1 uses the library eventmachine in an insecure way that does not have TLS hostname validation. This allows an attacker to perform a man-in-the-middle attack.

EPSS

0.001

Percentile

30.3%

Related for OSV:GHSA-6HRM-JQP3-64CV