CVE Vulnerabilities

CVE-2019-12855

Improper Certificate Validation

Published: Jun 16, 2019 | Modified: Nov 07, 2023
CVSS 3.x
7.4
HIGH
Source:
NVD
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
CVSS 2.x
5.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:N
RedHat/V2
RedHat/V3
7.4 MODERATE
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Ubuntu
LOW

In words.protocols.jabber.xmlstream in Twisted through 19.2.1, XMPP support did not verify certificates when used with TLS, allowing an attacker to MITM connections.

Weakness

The product does not validate, or incorrectly validates, a certificate.

Affected Software

Name Vendor Start Version End Version
Twisted Twistedmatrix * 19.2.1 (including)
Twisted Ubuntu bionic *
Twisted Ubuntu cosmic *
Twisted Ubuntu devel *
Twisted Ubuntu disco *
Twisted Ubuntu eoan *
Twisted Ubuntu trusty *
Twisted Ubuntu trusty/esm *
Twisted Ubuntu xenial *
Twisted-py3 Ubuntu trusty *

Potential Mitigations

References