PT-2019-7137 · Python · Python Twisted

CVE-2014-7143

·

Publicado

2019-11-12

·

Atualizado

2024-11-25

CVSS v4.0

8.7

Alta

VetorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Python Twisted version 14.0
Description The issue concerns the trustRoot in the HTTP client of Python Twisted, which is not respected. This means that the trust root, which is supposed to define the trusted certificate authorities, is not being properly considered, potentially leading to security issues.
Recommendations For Python Twisted version 14.0, consider updating to a version where this issue is fixed, as the current version does not respect the trustRoot in the HTTP client. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Certificate Validation

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2014-7143
GHSA-3C45-WGJP-7V9R
PYSEC-2019-212

Produtos afetados

Python Twisted