VDB
KO

PYSEC-2019-129

Details

In words.protocols.jabber.xmlstream in Twisted through 19.2.1, XMPP support did not verify certificates when used with TLS, allowing an attacker to MITM connections.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI / twisted
Introduced in: 0 Fixed in: 19.7.0rc1
Fix pip install --upgrade 'twisted>=19.7.0rc1'

References