CVE-2020-15134
Last modified
CVE-2020-15134 is a high-severity vulnerability rated 8.7/10 on the CVSS scale. Faye before version 1.4.0, there is a lack of certification validation in TLS handshakes. Faye uses em-http-request and faye-websocket in the Ruby version of its client. EPSS estimates a 0.86% chance of exploitation in the next 30 days.
Description
Faye before version 1.4.0, there is a lack of certification validation in TLS handshakes. Faye uses em-http-request and faye-websocket in the Ruby version of its client. Those libraries both use the `EM::Connection#start_tls` method in EventMachine to implement the TLS handshake whenever a `wss:` URL is used for the connection. This method does not implement certificate verification by default, meaning that it does not check that the server presents a valid and trusted TLS certificate for the expected hostname. That means that any `https:` or `wss:` connection made using these libraries is vulnerable to a man-in-the-middle attack, since it does not confirm the identity of the server it is connected to. The first request a Faye client makes is always sent via normal HTTP, but later messages may be sent via WebSocket. Therefore it is vulnerable to the same problem that these underlying libraries are, and we needed both libraries to support TLS verification before Faye could claim to do the same. Your client would still be insecure if its initial HTTPS request was verified, but later WebSocket connections were not. This is fixed in Faye v1.4.0, which enables verification by default. For further background information on this issue, please see the referenced GitHub Advisory.
Metrics
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Faye Project | Faye | < 1.4.0 |
References
- https://blog.jcoglan.com/2020/07/31/missing-tls-verification-in-faye/Exploit, Third Party Advisory
- https://github.com/faye/faye/security/advisories/GHSA-3q49-h8f9-9fr9Exploit, Third Party Advisory
- https://blog.jcoglan.com/2020/07/31/missing-tls-verification-in-faye/Exploit, Third Party Advisory
- https://github.com/faye/faye/security/advisories/GHSA-3q49-h8f9-9fr9Exploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2020-15134?
How severe is CVE-2020-15134?
How do I fix CVE-2020-15134?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2020
- CVE-2020-15129In Traefik before versions 1.7.26, 2.2.8, and 2.3.0-rc3, the…4.7
- CVE-2020-1513An elevation of privilege vulnerability exists when the Wind…7.8
- CVE-2020-15130In SLPJS (npm package slpjs) before version 0.27.4, there is…7.5
- CVE-2020-15131In SLP Validate (npm package slp-validate) before version 1.…7.5
- CVE-2020-15132In Sulu before versions 1.6.35, 2.0.10, and 2.1.1, when the …5.3
- CVE-2020-15133In faye-websocket before version 0.11.0, there is a lack of …8.7
- CVE-2020-15135save-server (npm package) before version 1.05 is affected by…7.6
- CVE-2020-15136In ectd before versions 3.4.10 and 3.3.23, gateway TLS authe…6.5
- CVE-2020-15137All versions of HoRNDIS are affected by an integer overflow …5.9
- CVE-2020-15138Prism is vulnerable to Cross-Site Scripting. The easing prev…7.5
- CVE-2020-15139In MyBB before version 1.8.24, the custom MyCode (BBCode) fo…6.1
- CVE-2020-1514<p>A cross-site-scripting (XSS) vulnerability exists when Mi…5.4
Are you affected by CVE-2020-15134?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
