id: PYSEC-2012-17 details: Tweepy does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate, related to use of the Python httplib library. affected: - package: name: tweepy ecosystem: PyPI purl: pkg:pypi/tweepy ranges: - type: ECOSYSTEM events: - introduced: "0" - fixed: 2.3.1 versions: - "1.1" - "1.10" - "1.11" - "1.12" - "1.13" - "1.2" - "1.3" - "1.4" - "1.5" - "1.6" - 1.7.1 - "1.8" - "1.9" - "2.0" - "2.1" - "2.2" - "2.3" - 2.3.0 references: - type: WEB url: http://www.cs.utexas.edu/~shmat/shmat_ccs12.pdf - type: WEB url: https://exchange.xforce.ibmcloud.com/vulnerabilities/79831 - type: ADVISORY url: https://github.com/advisories/GHSA-pwx5-xg7g-wpc5 aliases: - CVE-2012-5825 - GHSA-pwx5-xg7g-wpc5 modified: "2021-08-27T03:22:49.526995Z" published: "2012-11-04T22:55:00Z"