PT-2019-7137 · Python · Python Twisted

Published

2019-11-12

·

Updated

2024-11-25

·

CVE-2014-7143

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Python Twisted version 14.0
Description The issue concerns the trustRoot in the HTTP client of Python Twisted, which is not respected. This means that the trust root, which is supposed to define the trusted certificate authorities, is not being properly considered, potentially leading to security issues.
Recommendations For Python Twisted version 14.0, consider updating to a version where this issue is fixed, as the current version does not respect the trustRoot in the HTTP client. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Certificate Validation

Weakness Enumeration

Related Identifiers

CVE-2014-7143
GHSA-3C45-WGJP-7V9R
PYSEC-2019-212

Affected Products

Python Twisted