EM-HTTP-Request 1.1.5 uses the library eventmachine in an insecure way that allows an attacker to perform a man-in-the-middle attack against users of the library. The hostname in a TLS server certificate is not verified.
| Software | From | Fixed in |
|---|---|---|
| em-http-request_project / em-http-request | 1.1.5 | 1.1.5.x |
| fedoraproject / fedora | 32 | 32.x |
| fedoraproject / fedora | 33 | 33.x |
em-http-request
|
- | 1.1.6 |