—
PYSEC-2022-43013
Quick fix
PYSEC-2022-43013 — slixmpp: upgrade to the fixed version with the command below.
pip install --upgrade 'slixmpp>=1.8.3'Details
Slixmpp before 1.8.3 lacks SSL Certificate hostname validation in XMLStream, allowing an attacker to pose as any server in the eyes of Slixmpp.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://github.com/poezio/slixmpp/commits/master/slixmpp/xmlstream/xmlstream.py[WEB]
- https://github.com/poezio/slixmpp/tags[WEB]
- https://lab.louiz.org/poezio/slixmpp/-/commits/master[WEB]
- https://lab.louiz.org/poezio/slixmpp/-/commit/b60b1b985db928532f97c4f61d6fbc801f0aa7fa[WEB]
- https://github.com/advisories/GHSA-q6cq-m9gm-6q2f[ADVISORY]