TweetStream 2.6.1 uses the library eventmachine in an insecure way that does not have TLS hostname validation. This allows an attacker to perform a man-in-the-middle attack.
Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-24393
Reference (s):
- https://github.com/tweetstream/tweetstream
- https://securitylab.github.com/advisories/GHSL-2020-096-tweetstream-tweetstream

