PYSEC-2019-129
Dashboard / Vulnerabilities / PYSEC-2019-129
PYSEC-2019-129
Summary:
Details: In words.protocols.jabber.xmlstream in Twisted through 19.2.1, XMPP support did not verify certificates when used with TLS, allowing an attacker to MITM connections.
References: https://twistedmatrix.com/trac/ticket/9561, https://github.com/twisted/twisted/pull/1147, https://lists.fedoraproject.org/archives/list/[email protected]/message/PLTZDMFBNFSJMBXYJNGJHENJA4H2TSMZ/, http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00013.html, http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00028.html, https://usn.ubuntu.com/4308-1/, https://usn.ubuntu.com/4308-2/, https://www.oracle.com/security-alerts/cpuapr2020.html, https://github.com/advisories/GHSA-65rm-h285-5cc5
Affected packages
Package
Name: twisted
Purl: pkg:pypi/twisted
Affected ranges
Type: ECOSYSTEM
Events:
