CVE-2019-16263

Published
View on NVD ↗
CVSS v3
7.4
HIGH
CVSS v2
5.8
MEDIUM
Affected
1
PROJECT

Description

The Twitter Kit framework through 3.4.2 for iOS does not properly validate the api.twitter.com SSL certificate. Although the certificate chain must contain one of a set of pinned certificates, there are certain implementation errors such as a lack of hostname verification. NOTE: this is an end-of-life product.

Twitter Kit is a native SDK to include Twitter content inside mobile apps.
GitHubGitHub
698