Show plain JSON{"id": "CVE-2019-16263", "cveTags": [], "metrics": {"cvssMetricV2": [{"type": "Primary", "source": "nvd@nist.gov", "cvssData": {"version": "2.0", "baseScore": 5.8, "accessVector": "NETWORK", "vectorString": "AV:N/AC:M/Au:N/C:P/I:P/A:N", "authentication": "NONE", "integrityImpact": "PARTIAL", "accessComplexity": "MEDIUM", "availabilityImpact": "NONE", "confidentialityImpact": "PARTIAL"}, "acInsufInfo": false, "impactScore": 4.9, "baseSeverity": "MEDIUM", "obtainAllPrivilege": false, "exploitabilityScore": 8.6, "obtainUserPrivilege": false, "obtainOtherPrivilege": false, "userInteractionRequired": false}], "cvssMetricV31": [{"type": "Primary", "source": "nvd@nist.gov", "cvssData": {"scope": "UNCHANGED", "version": "3.1", "baseScore": 7.4, "attackVector": "NETWORK", "baseSeverity": "HIGH", "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N", "integrityImpact": "HIGH", "userInteraction": "NONE", "attackComplexity": "HIGH", "availabilityImpact": "NONE", "privilegesRequired": "NONE", "confidentialityImpact": "HIGH"}, "impactScore": 5.2, "exploitabilityScore": 2.2}]}, "published": "2019-10-07T12:15:11.680", "references": [{"url": "https://blog.appicaptor.com/2019/10/04/vulnerable-library-warning-twitterkit-for-ios/", "tags": ["Third Party Advisory"], "source": "cve@mitre.org"}, {"url": "https://github.com/twitter-archive/twitter-kit-ios/blob/ac42e1351a66afa5ff7718d04d64a905dafe1f41/TwitterCore/TwitterCore/Networking/Security/TWTRServerTrustEvaluator.m#L75-L81", "tags": ["Third Party Advisory"], "source": "cve@mitre.org"}, {"url": "https://www.sit.fraunhofer.de/fileadmin/dokumente/CVE/Advisory_TwitterKit_for_iOS_CVE-2019-16263.pdf", "tags": ["Exploit", "Third Party Advisory"], "source": "cve@mitre.org"}], "vulnStatus": "Analyzed", "weaknesses": [{"type": "Primary", "source": "nvd@nist.gov", "description": [{"lang": "en", "value": "CWE-295"}]}], "descriptions": [{"lang": "en", "value": "The Twitter Kit framework through 3.4.2 for iOS does not properly validate the api.twitter.com SSL certificate. Although the certificate chain must contain one of a set of pinned certificates, there are certain implementation errors such as a lack of hostname verification. NOTE: this is an end-of-life product."}, {"lang": "es", "value": "El framework Twitter Kit versiones hasta 3.4.2 para iOS no comprueba apropiadamente el certificado SSL de api.twitter.com. Aunque la cadena de certificados debe contener uno de un conjunto de certificados anclados, se presentan determinados errores de implementaci\u00f3n, tales como la falta de comprobaci\u00f3n del hostname. NOTA: este es un producto al final de su vida \u00fatil."}], "lastModified": "2019-10-09T17:45:12.963", "configurations": [{"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:a:twitter:twitter_kit:*:*:*:*:*:iphone_os:*:*", "vulnerable": true, "matchCriteriaId": "9BEB6B70-78DD-40DF-9A1A-30EFE6598161", "versionEndIncluding": "3.4.2"}], "operator": "OR"}]}], "sourceIdentifier": "cve@mitre.org"}