Описание
In words.protocols.jabber.xmlstream in Twisted through 19.2.1, XMPP support did not verify certificates when used with TLS, allowing an attacker to MITM connections.
Отчет
- This issue affects the version of calamari-server(embeds python-twisted) as shipped with Red Hat Ceph Storage 2 as it does not check for TLS certificate.
- This issue did not affect the versions of python-twisted-core as shipped with Red Hat Gluster Storage 3, Red Hat Ceph Storage 2 and 3 as it does not ship XMPP XML Stream bits. This issue affects the versions of python-twisted-words as shipped with Red Hat Enterprise Linux 6 and 7. Red Hat Enterprise Linux 6 is now in Maintenance Support 2 Phase of the support and maintenance life cycle. This has been rated as having a security impact of Moderate, and is not currently planned to be addressed in future updates. For additional information, refer to the Red Hat Enterprise Linux Life Cycle: https://access.redhat.com/support/policy/updates/errata/. Red Hat OpenStack Platform:
- This flaw depends on the use of the XMPP protocol, which is not used in Red Hat OpenStack Platform. Although updating is recommended for affected versions, Red Hat OpenStack Platform environments are not vulnerable. Because of this and the lower product impact, no fixes will be issued for any Red Hat OpenStack Platform version at this time.
- Because the flaw's impact is Low, it will not be fixed in Red Hat OpenStack Platform 9 which will retire shortly after the public date.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
Red Hat Ceph Storage 2 | calamari-server | Affected | ||
Red Hat Ceph Storage 2 | python-twisted-core | Not affected | ||
Red Hat Ceph Storage 3 | python-twisted-core | Not affected | ||
Red Hat Enterprise Linux 6 | python-twisted-words | Out of support scope | ||
Red Hat Enterprise Linux 7 | python-twisted-words | Will not fix | ||
Red Hat OpenStack Platform 10 (Newton) | python-twisted | Will not fix | ||
Red Hat OpenStack Platform 13 (Queens) | python-twisted | Will not fix | ||
Red Hat OpenStack Platform 14 (Rocky) | python-twisted | Out of support scope | ||
Red Hat OpenStack Platform 9 (Mitaka) | python-twisted | Will not fix | ||
Red Hat OpenStack Platform 9 (Mitaka) Operational Tools | python-twisted | Will not fix |
Показывать по
10
Дополнительная информация
Статус:
Moderate
Дефект:
CWE-295
https://bugzilla.redhat.com/show_bug.cgi?id=1728206python-twisted: XMPP support in words.protocols.jabber.xmlstream in Twisted does not verify certificates allowing for a MITM connections
EPSS
Процентиль: 67%
0.00548
Низкий
7.4 High
CVSS3
Связанные уязвимости
CVSS3: 7.4
ubuntu
около 6 лет назад
In words.protocols.jabber.xmlstream in Twisted through 19.2.1, XMPP support did not verify certificates when used with TLS, allowing an attacker to MITM connections.
CVSS3: 7.4
nvd
около 6 лет назад
In words.protocols.jabber.xmlstream in Twisted through 19.2.1, XMPP support did not verify certificates when used with TLS, allowing an attacker to MITM connections.
CVSS3: 7.4
debian
около 6 лет назад
In words.protocols.jabber.xmlstream in Twisted through 19.2.1, XMPP su ...
EPSS
Процентиль: 67%
0.00548
Низкий
7.4 High
CVSS3