logo

CVE-2016-9015 urllib3

Package

Manager: pip
Name: urllib3
Vulnerable Version: >=1.17 <1.18.1

Severity

Level: Medium

CVSS v3.1: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N

CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N

EPSS: 0.00173 pctl0.39057

Details

Urllib3 Incorrect Certificate Validation Versions 1.17 and 1.18 of the Python urllib3 library suffer from a vulnerability that can cause them, in certain configurations, to not correctly validate TLS certificates. This places users of the library with those configurations at risk of man-in-the-middle and information leakage attacks. This vulnerability affects users using versions 1.17 and 1.18 of the urllib3 library, who are using the optional PyOpenSSL support for TLS instead of the regular standard library TLS backend, and who are using OpenSSL 1.1.0 via PyOpenSSL. This is an extremely uncommon configuration, so the security impact of this vulnerability is low.

Metadata

Created: 2022-05-17T03:05:04Z
Modified: 2024-11-18T22:58:27Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-v4w5-p2hg-8fh6/GHSA-v4w5-p2hg-8fh6.json
CWE IDs: ["CWE-295"]
Alternative ID: GHSA-v4w5-p2hg-8fh6
Finding: F163
Auto approve: 1