In words.protocols.jabber.xmlstream in Twisted through 19.2.1, XMPP support did not verify certificates when used with TLS, allowing an attacker to MITM connections.
| Score | Percentile |
|---|---|
| 0.65% | 70.65% |
| Base score | Version | Severity | Vector |
|---|---|---|---|
| 7.4 | 3.0 | — |
|
| 9.1 | 4.0 | — |
|
| Type | Value |
|---|---|
| GHSA | GHSA-65rm-h285-5cc5 ↗ |
| CVE | CVE-2019-12855 ↗ |
| CWE id | Name |
|---|---|
| CWE-295 | Improper Certificate Validation |
Vulnerable version ranges and first patched releases as published by GitHub.
| Ecosystem | Package | Vulnerable range | First patched | Vulnerable functions |
|---|---|---|---|---|
| pip | twisted | >= 0, < 19.7.0rc1 | 19.7.0rc1 | — |