Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-65rm-h285-5cc5

Опубликовано: 16 авг. 2019
Источник: github
Github: Прошло ревью
CVSS4: 9.1
CVSS3: 7.4

Описание

Improper Certificate Validation in Twisted

In words.protocols.jabber.xmlstream in Twisted through 19.2.1, XMPP support did not verify certificates when used with TLS, allowing an attacker to MITM connections.

Пакеты

Наименование

Twisted

pip
Затронутые версииВерсия исправления

< 19.7.0rc1

19.7.0rc1

EPSS

Процентиль: 67%
0.00548
Низкий

9.1 Critical

CVSS4

7.4 High

CVSS3

Дефекты

CWE-295

Связанные уязвимости

CVSS3: 7.4
ubuntu
около 6 лет назад

In words.protocols.jabber.xmlstream in Twisted through 19.2.1, XMPP support did not verify certificates when used with TLS, allowing an attacker to MITM connections.

CVSS3: 7.4
redhat
около 6 лет назад

In words.protocols.jabber.xmlstream in Twisted through 19.2.1, XMPP support did not verify certificates when used with TLS, allowing an attacker to MITM connections.

CVSS3: 7.4
nvd
около 6 лет назад

In words.protocols.jabber.xmlstream in Twisted through 19.2.1, XMPP support did not verify certificates when used with TLS, allowing an attacker to MITM connections.

CVSS3: 7.4
msrc
около 4 лет назад

Описание отсутствует

CVSS3: 7.4
debian
около 6 лет назад

In words.protocols.jabber.xmlstream in Twisted through 19.2.1, XMPP su ...

EPSS

Процентиль: 67%
0.00548
Низкий

9.1 Critical

CVSS4

7.4 High

CVSS3

Дефекты

CWE-295