CVE-2019-12855
In words.protocols.jabber.xmlstream in Twisted through 19.2.1, XMPP support did not verify certificates when used with TLS, allowing an attacker to MITM connections.
02 / AFFECTED SOFTWARE
Affected packages
3 explicit affected versions
71 explicit affected versions
71 explicit affected versions
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
In words.protocols.jabber.xmlstream in Twisted through 19.2.1, XMPP support did not verify certificates when used with TLS, allowing an attacker to MITM connections.
In words.protocols.jabber.xmlstream in Twisted through 19.2.1, XMPP support did not verify certificates when used with TLS, allowing an attacker to MITM connections.
In words.protocols.jabber.xmlstream in Twisted through 19.2.1, XMPP support did not verify certificates when used with TLS, allowing an attacker to MITM connections.
05 / REFERENCES
Further evidence
- http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00013.html
- http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00028.html
- https://github.com/twisted/twisted/pull/1147
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PLTZDMFBNFSJMBXYJNGJHENJA4H2TSMZ/
- https://twistedmatrix.com/trac/ticket/9561
- https://usn.ubuntu.com/4308-1/
- https://usn.ubuntu.com/4308-2/
- https://www.oracle.com/security-alerts/cpuapr2020.html
- https://github.com/pypa/advisory-database/tree/main/vulns/twisted/PYSEC-2019-129.yaml
- https://github.com/twisted/twisted
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PLTZDMFBNFSJMBXYJNGJHENJA4H2TSMZ
- https://lists.fedoraproject.org/archives/list/[email protected]/message/PLTZDMFBNFSJMBXYJNGJHENJA4H2TSMZ
- https://nvd.nist.gov/vuln/detail/CVE-2019-12855
- https://usn.ubuntu.com/4308-1
- https://usn.ubuntu.com/4308-2
- https://github.com/advisories/GHSA-65rm-h285-5cc5
- https://lists.fedoraproject.org/archives/list/[email protected]/message/PLTZDMFBNFSJMBXYJNGJHENJA4H2TSMZ/