Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2022-2996

Опубликовано: 01 сент. 2022
Источник: debian
EPSS Низкий

Описание

A flaw was found in the python-scciclient when making an HTTPS connection to a server where the server's certificate would not be verified. This issue opens up the connection to possible Man-in-the-middle (MITM) attacks.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
python-scciclientfixed0.12.3-2package
python-scciclientno-dsabullseyepackage

Примечания

  • https://opendev.org/x/python-scciclient/commit/274dca0344b65b4ac113d3271d21c17e970a636c (0.12)

EPSS

Процентиль: 41%
0.00194
Низкий

Связанные уязвимости

CVSS3: 7.4
ubuntu
больше 3 лет назад

A flaw was found in the python-scciclient when making an HTTPS connection to a server where the server's certificate would not be verified. This issue opens up the connection to possible Man-in-the-middle (MITM) attacks.

CVSS3: 7.4
redhat
больше 3 лет назад

A flaw was found in the python-scciclient when making an HTTPS connection to a server where the server's certificate would not be verified. This issue opens up the connection to possible Man-in-the-middle (MITM) attacks.

CVSS3: 7.4
nvd
больше 3 лет назад

A flaw was found in the python-scciclient when making an HTTPS connection to a server where the server's certificate would not be verified. This issue opens up the connection to possible Man-in-the-middle (MITM) attacks.

CVSS3: 7.4
github
больше 3 лет назад

python-scciclient vulnerable to Man-in-the-middle (MITM) attacks

EPSS

Процентиль: 41%
0.00194
Низкий