CVE-2019-12855Improper Certificate Validation in Twisted

Severity
7.4HIGHNVD
OSV6.1
EPSS
0.6%
top 29.24%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJun 16
Latest updateMar 30

Description

In words.protocols.jabber.xmlstream in Twisted through 19.2.1, XMPP support did not verify certificates when used with TLS, allowing an attacker to MITM connections.

CVSS vector

CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:NExploitability: 2.2 | Impact: 5.2

Affected Packages4 packages

PyPItwisted/twisted< 19.7.0rc1
Debiantwisted/twisted< 18.9.0-7+3
Ubuntutwisted/twisted< 16.0.0-1ubuntu0.4+1
NVDtwisted/twisted19.2.1

Patches

🔴Vulnerability Details

6
OSV
twisted vulnerabilities2020-03-30
OSV
twisted vulnerabilities2020-03-19
OSV
Improper Certificate Validation in Twisted2019-08-16
GHSA
Improper Certificate Validation in Twisted2019-08-16
OSV
CVE-2019-12855: In words2019-06-16

📋Vendor Advisories

5
Ubuntu
Twisted vulnerabilities2020-03-30
Ubuntu
Twisted vulnerabilities2020-03-19
Red Hat
python-twisted: XMPP support in words.protocols.jabber.xmlstream in Twisted does not verify certificates allowing for a MITM connections2019-07-09
Microsoft
In words.protocols.jabber.xmlstream in Twisted through 19.2.1 XMPP support did not verify certificates when used with TLS allowing an attacker to MITM connections.2019-06-11
Debian
CVE-2019-12855: twisted - In words.protocols.jabber.xmlstream in Twisted through 19.2.1, XMPP support did ...2019

💬Community

3
Bugzilla
CVE-2019-12855 python-twisted: XMPP support in words.protocols.jabber.xmlstream in Twisted does not verify certificates allowing for a MITM connections [openstack-rdo]2019-08-13
Bugzilla
CVE-2019-12855 python-twisted: XMPP support in words.protocols.jabber.xmlstream in Twisted does not verify certificates allowing for a MITM connections2019-07-09
Bugzilla
CVE-2019-12855 python-twisted: XMPP support in words.protocols.jabber.xmlstream in Twisted does not verify certificates allowing for a MITM connections [fedora-all]2019-07-09
CVE-2019-12855 — Improper Certificate Validation | cvebase