Improper Certificate Validation in Twisted Web - CVE-2019-12855

 

Improper Certificate Validation in Twisted Web - CVE-2019-12855

Published: June 16, 2019 / Updated: August 3, 2020


Vulnerability identifier: #VU33150
CSH Severity: Medium
CVSS v4: 9.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-12855
CWE-ID: CWE-295
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to read and manipulate data.

In words.protocols.jabber.xmlstream in Twisted through 19.2.1, XMPP support did not verify certificates when used with TLS, allowing an attacker to MITM connections.


Affected software

Twisted Web
SUSE Linux
Opensuse
Fedora
py3-twisted (Alpine package)
python-twisted

How to mitigate CVE-2019-12855

Install update from vendor's website.

Twisted Web - update to 19.7.0
py3-twisted (Alpine package) - update to 20.3.0-r0
python-twisted - update to 19.2.1-3.fc30

External References

Related Security Bulletins