High severityNVD Advisory· Published May 2, 2014· Updated Jun 17, 2026
CVE-2013-7110
CVE-2013-7110
Description
Transifex command-line client before 0.10 does not validate X.509 certificates for data transfer connections, which allows man-in-the-middle attackers to spoof a Transifex server via an arbitrary certificate. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-2073.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
transifex-clientPyPI | < 0.10 | 0.10 |
Affected products
10cpe:2.3:a:transifex:transifex:*:*:*:*:*:*:*:*+ 8 more
- cpe:2.3:a:transifex:transifex:*:*:*:*:*:*:*:*range: <=0.9
- cpe:2.3:a:transifex:transifex:0.1:*:*:*:*:*:*:*
- cpe:2.3:a:transifex:transifex:0.2:*:*:*:*:*:*:*
- cpe:2.3:a:transifex:transifex:0.3:*:*:*:*:*:*:*
- cpe:2.3:a:transifex:transifex:0.4:*:*:*:*:*:*:*
- cpe:2.3:a:transifex:transifex:0.5:*:*:*:*:*:*:*
- cpe:2.3:a:transifex:transifex:0.6:*:*:*:*:*:*:*
- cpe:2.3:a:transifex:transifex:0.7:*:*:*:*:*:*:*
- cpe:2.3:a:transifex:transifex:0.8:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
7- github.com/advisories/GHSA-jf99-2rj4-jxrmghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2013-7110ghsaADVISORY
- www.openwall.com/lists/oss-security/2013/12/13/5nvdWEB
- www.openwall.com/lists/oss-security/2013/12/15/3nvdWEB
- github.com/pypa/advisory-database/tree/main/vulns/transifex-client/PYSEC-2014-72.yamlghsaWEB
- github.com/transifex/transifex-client/commit/e0d1f8b38ec1a24e2999d63420554d8393206f58ghsaWEB
- github.com/transifex/transifex-client/issues/42nvdWEB
News mentions
0No linked articles in our index yet.