CVE-2020-24393: Tweetstream Project Tweetstream
Medium severity, CVSS 5.9. EPSS: 0.9% chance of exploitation in the next 30 days.
TweetStream 2.6.1 uses the library eventmachine in an insecure way that does not have TLS hostname validation. This allows an attacker to perform a man-in-the-middle attack.
Affected products
- Tweetstream Project Tweetstream: version 2.6.1 only
Published 2021-02-19. Last modified 2026-06-17.