CVE Vulnerabilities

CVE-2019-12855

Improper Certificate Validation

Published: Jun 16, 2019 | Modified: Nov 25, 2024
CVSS 3.x
7.4
HIGH
Source:
NVD
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
CVSS 2.x
5.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:N
RedHat/V2
RedHat/V3
7.4 MODERATE
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Ubuntu
LOW
root.io logo minimus.io logo echo.ai logo

In words.protocols.jabber.xmlstream in Twisted through 19.2.1, XMPP support did not verify certificates when used with TLS, allowing an attacker to MITM connections.

Weakness

The product does not validate, or incorrectly validates, a certificate.

Affected Software

NameVendorStart VersionEnd Version
TwistedTwisted*19.2.1 (including)
TwistedUbuntubionic*
TwistedUbuntucosmic*
TwistedUbuntudevel*
TwistedUbuntudisco*
TwistedUbuntueoan*
TwistedUbuntuesm-infra-legacy/trusty*
TwistedUbuntuesm-infra/bionic*
TwistedUbuntuesm-infra/xenial*
TwistedUbuntutrusty*
TwistedUbuntutrusty/esm*
TwistedUbuntuxenial*
Twisted-py3Ubuntutrusty*

Potential Mitigations

References