Improper Certificate Validation in Twisted
Critical severity
GitHub Reviewed
Published
Aug 16, 2019
to the GitHub Advisory Database
•
Updated Nov 25, 2024
Description
Published by the National Vulnerability Database
Jun 16, 2019
Reviewed
Aug 12, 2019
Published to the GitHub Advisory Database
Aug 16, 2019
Last updated
Nov 25, 2024
In words.protocols.jabber.xmlstream in Twisted through 19.2.1, XMPP support did not verify certificates when used with TLS, allowing an attacker to MITM connections.
References