CVE-2019-12855 PUBLISHED

In words.protocols.jabber.xmlstream in Twisted through 19.2.1, XMPP support did not verify certificates when used with TLS, allowing an attacker to MITM connections.

EPSS 0.66% · 70.9th percentile

Risk Scores

EPSS Score
0.66%
70.9th percentile

Affected Products

VendorProductVersions
Ubuntu:18.04:LTStwisted17.9.0-1, 16.6.0-2ubuntu3, 0
Ubuntu:16.04:LTStwisted15.5.0-2, 15.5.0-2ubuntu1, 15.5.0-4
Ubuntu:Pro:14.04:LTStwisted0, 13.2.0-1ubuntu1.2, 13.2.0-1ubuntu1

Timeline

References

Open in Interactive Console →