VYPR

Twitter Kit

by Twitter

CVEs (3)

  • CVE-2019-16263HigOct 7, 2019
    risk 0.48cvss 7.4epss 0.01

    The Twitter Kit framework through 3.4.2 for iOS does not properly validate the api.twitter.com SSL certificate. Although the certificate chain must contain one of a set of pinned certificates, there are certain implementation errors such as a lack of hostname verification. NOTE:…

  • CVE-2019-5431MedMay 6, 2019
    risk 0.35cvss 5.4epss 0.00

    This vulnerability was caused by an incomplete fix to CVE-2017-0911. Twitter Kit for iOS versions 3.0 to 3.4.0 is vulnerable to a callback verification flaw in the "Login with Twitter" component allowing an attacker to provide alternate credentials. In the final step of "Login…

  • CVE-2017-0911MedFeb 9, 2018
    risk 0.35cvss 5.4epss 0.01

    Twitter Kit for iOS versions 3.0 to 3.2.1 is vulnerable to a callback verification flaw in the "Login with Twitter" component allowing an attacker to provide alternate credentials. In the final step of "Login with Twitter" authentication information is passed back to the…