VYPR
Moderate severityNVD Advisory· Published Feb 19, 2021· Updated Aug 4, 2024

CVE-2020-24392

CVE-2020-24392

Description

In voloko twitter-stream 0.1.10, missing TLS hostname validation allows an attacker to perform a man-in-the-middle attack against users of the library (because eventmachine is misused).

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
twitter-streamRubyGems
<= 0.1.16

Affected products

2

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.