Publish GHSA-4f68-49qq-h392

This commit is contained in:
advisory-database[bot]
2023-09-05 21:49:08 +00:00
parent 0a120c8c80
commit 7ec4021808
@@ -1,12 +1,12 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4f68-49qq-h392",
"modified": "2023-01-23T20:29:20Z",
"modified": "2023-09-05T21:47:52Z",
"published": "2021-05-24T18:12:20Z",
"aliases": [
"CVE-2020-13163"
],
"summary": "Improper certificate validation in em-map",
"summary": "Improper certificate validation in em-imap",
"details": "em-imap 0.5 and earlier use the library eventmachine in an insecure way that allows an attacker to perform a man-in-the-middle attack against users of the library. The hostname in a TLS server certificate is not verified.",
"severity": [
{
@@ -20,6 +20,11 @@
"ecosystem": "RubyGems",
"name": "em-imap"
},
"ecosystem_specific": {
"affected_functions": [
""
]
},
"ranges": [
{
"type": "ECOSYSTEM",