CVE-2019-12855

Related Vulnerabilities: CVE-2019-12855  

Impact: Important Public Date: 2019-07-09 CWE: CWE-295 Bugzilla: 1728206: CVE-2019-12855 python-twisted: XMPP support in words.protocols.jabber.xmlstream in Twisted does not verify certificates allowing for a MITM connections In words.protocols.jabber.xmlstream in Twisted through 19.2.1, XMPP support did not verify certificates when used with TLS, allowing an attacker to MITM connections.

The MITRE CVE dictionary describes this issue as:

In words.protocols.jabber.xmlstream in Twisted through 19.2.1, XMPP support did not verify certificates when used with TLS, allowing an attacker to MITM connections.

Find out more about CVE-2019-12855 from the MITRE CVE dictionary dictionary and NIST NVD.

CVSS v3 metrics

NOTE: The following CVSS v3 metrics and score provided are preliminary and subject to review.

CVSS3 Base Score 7.4
CVSS3 Base Metrics CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Attack Vector Network
Attack Complexity High
Privileges Required None
User Interaction None
Scope Unchanged
Confidentiality High
Integrity Impact High
Availability Impact None

Affected Packages State

Platform Package State
Red Hat OpenStack Platform Operational Tools 9 python-twisted Under investigation
Red Hat OpenStack Platform 9.0 python-twisted Under investigation
Red Hat OpenStack Platform 14.0 (Rocky) python-twisted Under investigation
Red Hat OpenStack Platform 13.0 (Queens) python-twisted Under investigation
Red Hat OpenStack Platform 10 python-twisted Under investigation
Red Hat Gluster Storage 3 python-twisted-core Under investigation
Red Hat Enterprise Linux OpenStack Platform 8.0 Operational Tools for RHEL 7 python-twisted Under investigation
Red Hat Enterprise Linux 7 python-twisted-web Under investigation
Red Hat Enterprise Linux 6 python-twisted-web Under investigation
Red Hat Ceph Storage 3 python-twisted-core Under investigation
Red Hat Ceph Storage 2 python-twisted-core Under investigation
Red Hat Ceph Storage 2 calamari-server Under investigation