THREAT OPS › Threat News › [NVD] CVE-2012-5825 (HIGH 7.4) — Tweepy does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate, related to use of the Python
[NVD] CVE-2012-5825 (HIGH 7.4) — Tweepy does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate, related to use of the Python
CVE-2012-5825 CVSS: 7.4 HIGH Published: 2012-11-04T22:55:04.997
Tweepy does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate, related to use of the Python httplib library.
Indicators of compromise
- CVE-2012-5825cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2012-5825