VDB
Sign up
—

PYSEC-2022-43013

Quick fix

PYSEC-2022-43013 — slixmpp: upgrade to the fixed version with the command below.

pip install --upgrade 'slixmpp>=1.8.3'

Details

Slixmpp before 1.8.3 lacks SSL Certificate hostname validation in XMLStream, allowing an attacker to pose as any server in the eyes of Slixmpp.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/slixmpp
Introduced in: 0Fixed in: 1.8.3
Fixpip install --upgrade 'slixmpp>=1.8.3'

References