Restkit · Restkit · CVE-2015-2674
**Name of the Vulnerable Software and Affected Versions**
Restkit (affected versions not specified)
**Description**
The issue allows man-in-the-middle attackers to spoof TLS servers by leveraging the use of the `ssl.wrap socket` function in Python with the default CERT NONE value for the `cert reqs` argument. This enables attackers to intercept and alter communication between the client and server.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.