CVE-2020-13482 describes a man-in-the-middle vulnerability in EM-HTTP-Request 1.1.5, affecting various em-http-request and Fedora projects. The flaw stems from the library's insecure use of eventmachine, specifically its failure to verify the hostname in TLS server certificates. With a CVSS score of 7.4 (High), this vulnerability could allow an unauthenticated attacker to intercept and manipulate communications, leading to high confidentiality and integrity impacts. While no active exploitation, public exploit code, or significant community discussion has been observed, organizations using affected versions should consider mitigation strategies.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.1.5CPE matchmatch criteria | cpe:2.3:a:em-http-request_project:em-http-request:1.1.5:*:*:*:*:*:*:* | ||
32CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:32:*:*:*:*:*:*:* | ||
33CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.