Improper Certificate Validation in Twisted Web - CVE-2019-12855
Published: June 16, 2019 / Updated: August 3, 2020
Vulnerability identifier: #VU33150
CSH Severity: Medium
CVSS v4: 9.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-12855
CWE-ID: CWE-295
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote non-authenticated attacker to read and manipulate data.
In words.protocols.jabber.xmlstream in Twisted through 19.2.1, XMPP support did not verify certificates when used with TLS, allowing an attacker to MITM connections.
Affected software
Twisted Web
SUSE Linux
Opensuse
Fedora
py3-twisted (Alpine package)
python-twisted
SUSE Linux
Opensuse
Fedora
py3-twisted (Alpine package)
python-twisted
How to mitigate CVE-2019-12855
Install update from vendor's website.
Twisted Web - update to 19.7.0
py3-twisted (Alpine package) - update to 20.3.0-r0
python-twisted - update to 19.2.1-3.fc30
py3-twisted (Alpine package) - update to 20.3.0-r0
python-twisted - update to 19.2.1-3.fc30
External References
- http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00013.html
- http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00028.html
- https://github.com/twisted/twisted/pull/1147
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/PLTZDMFBNFSJMBXYJNGJHENJA4H2TSMZ/
- https://twistedmatrix.com/trac/ticket/9561
- https://usn.ubuntu.com/4308-1/
- https://usn.ubuntu.com/4308-2/
- https://www.oracle.com/security-alerts/cpuapr2020.html