Lucene search

K
osvGoogleOSV:GHSA-Q27F-V3R6-9V77
HistoryMay 24, 2021 - 6:13 p.m.

Improper Certificate Validation in EM-HTTP-Request

2021-05-2418:13:13
Google
osv.dev
13
certificate
validation
em-http-request
eventmachine
man-in-the-middle
attack
tls
server
hostname
insecure
library
software

EPSS

0.001

Percentile

39.4%

EM-HTTP-Request 1.1.5 uses the library eventmachine in an insecure way that allows an attacker to perform a man-in-the-middle attack against users of the library. The hostname in a TLS server certificate is not verified.