Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-12855

Опубликовано: 09 июл. 2019
Источник: redhat
CVSS3: 7.4
EPSS Низкий

Описание

In words.protocols.jabber.xmlstream in Twisted through 19.2.1, XMPP support did not verify certificates when used with TLS, allowing an attacker to MITM connections.

Отчет

  • This issue affects the version of calamari-server(embeds python-twisted) as shipped with Red Hat Ceph Storage 2 as it does not check for TLS certificate.
  • This issue did not affect the versions of python-twisted-core as shipped with Red Hat Gluster Storage 3, Red Hat Ceph Storage 2 and 3 as it does not ship XMPP XML Stream bits. This issue affects the versions of python-twisted-words as shipped with Red Hat Enterprise Linux 6 and 7. Red Hat Enterprise Linux 6 is now in Maintenance Support 2 Phase of the support and maintenance life cycle. This has been rated as having a security impact of Moderate, and is not currently planned to be addressed in future updates. For additional information, refer to the Red Hat Enterprise Linux Life Cycle: https://access.redhat.com/support/policy/updates/errata/. Red Hat OpenStack Platform:
  • This flaw depends on the use of the XMPP protocol, which is not used in Red Hat OpenStack Platform. Although updating is recommended for affected versions, Red Hat OpenStack Platform environments are not vulnerable. Because of this and the lower product impact, no fixes will be issued for any Red Hat OpenStack Platform version at this time.
  • Because the flaw's impact is Low, it will not be fixed in Red Hat OpenStack Platform 9 which will retire shortly after the public date.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Ceph Storage 2calamari-serverAffected
Red Hat Ceph Storage 2python-twisted-coreNot affected
Red Hat Ceph Storage 3python-twisted-coreNot affected
Red Hat Enterprise Linux 6python-twisted-wordsOut of support scope
Red Hat Enterprise Linux 7python-twisted-wordsWill not fix
Red Hat OpenStack Platform 10 (Newton)python-twistedWill not fix
Red Hat OpenStack Platform 13 (Queens)python-twistedWill not fix
Red Hat OpenStack Platform 14 (Rocky)python-twistedOut of support scope
Red Hat OpenStack Platform 9 (Mitaka)python-twistedWill not fix
Red Hat OpenStack Platform 9 (Mitaka) Operational Toolspython-twistedWill not fix

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-295
https://bugzilla.redhat.com/show_bug.cgi?id=1728206python-twisted: XMPP support in words.protocols.jabber.xmlstream in Twisted does not verify certificates allowing for a MITM connections

EPSS

Процентиль: 67%
0.00548
Низкий

7.4 High

CVSS3

Связанные уязвимости

CVSS3: 7.4
ubuntu
около 6 лет назад

In words.protocols.jabber.xmlstream in Twisted through 19.2.1, XMPP support did not verify certificates when used with TLS, allowing an attacker to MITM connections.

CVSS3: 7.4
nvd
около 6 лет назад

In words.protocols.jabber.xmlstream in Twisted through 19.2.1, XMPP support did not verify certificates when used with TLS, allowing an attacker to MITM connections.

CVSS3: 7.4
msrc
около 4 лет назад

Описание отсутствует

CVSS3: 7.4
debian
около 6 лет назад

In words.protocols.jabber.xmlstream in Twisted through 19.2.1, XMPP su ...

suse-cvrf
около 6 лет назад

Security update for python-Twisted

EPSS

Процентиль: 67%
0.00548
Низкий

7.4 High

CVSS3