First published: Mon Sep 18 2017(Updated: )
The Twitter iOS client versions 6.62 and 6.62.1 fail to validate Twitter's server certificates for the /1.1/help/settings.json configuration endpoint, permitting man-in-the-middle attackers the ability to view an application-only OAuth client token and potentially enable unreleased Twitter iOS app features.
Credit: support@hackerone.com
Affected Software | Affected Version | How to fix |
---|---|---|
=6.62 | ||
=6.62.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-10511 is considered a high-severity vulnerability due to its potential for man-in-the-middle attacks.
To fix CVE-2016-10511, update the Twitter iOS client to version 6.62.2 or later.
CVE-2016-10511 affects Twitter iOS client versions 6.62 and 6.62.1.
CVE-2016-10511 allows man-in-the-middle attackers to intercept sensitive data, such as an application-only OAuth client token.
Using the affected versions of the Twitter iOS client poses a security risk until the vulnerability is addressed through an update.