Man-in-the-Middle (MitM) Affecting em-imap package, versions >=0.0.0
Threat Intelligence
EPSS
0.2% (59th
percentile)
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-RUBY-EMIMAP-569726
- published 20 May 2020
- disclosed 19 May 2020
- credit Unknown
Introduced: 19 May 2020
CVE-2020-13163 Open this link in a new tabHow to fix?
A fix was pushed into the master
branch but not yet published.
Overview
em-imap is a gem that allows you to connect to an IMAP4rev1 server in a non-blocking fashion.
Affected versions of this package are vulnerable to Man-in-the-Middle (MitM). The hostname in a TLS server certificate is not verified. An attacker can assume the identity of a trusted server and introduce malicious data in an otherwise trusted place.
References
CVSS Scores
version 3.1