Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-f9q5-46qg-74x4

Опубликовано: 17 мая 2022
Источник: github
Github: Прошло ревью
CVSS4: 8.7
CVSS3: 7.5

Описание

PyWBEM TOCTOU vulnerability in certificate validation

PyWBEM 0.7 and earlier uses a separate connection to validate X.509 certificates, which allows man-in-the-middle attackers to spoof a peer via an arbitrary certificate.

Пакеты

Наименование

pywbem

pip
Затронутые версииВерсия исправления

< 0.8.1

0.8.1

EPSS

Процентиль: 57%
0.00345
Низкий

8.7 High

CVSS4

7.5 High

CVSS3

Дефекты

CWE-20

Связанные уязвимости

ubuntu
больше 11 лет назад

PyWBEM 0.7 and earlier uses a separate connection to validate X.509 certificates, which allows man-in-the-middle attackers to spoof a peer via an arbitrary certificate.

redhat
около 12 лет назад

PyWBEM 0.7 and earlier uses a separate connection to validate X.509 certificates, which allows man-in-the-middle attackers to spoof a peer via an arbitrary certificate.

nvd
больше 11 лет назад

PyWBEM 0.7 and earlier uses a separate connection to validate X.509 certificates, which allows man-in-the-middle attackers to spoof a peer via an arbitrary certificate.

msrc
5 месяцев назад

PyWBEM 0.7 and earlier uses a separate connection to validate X.509 certificates, which allows man-in-the-middle attackers to spoof a peer via an arbitrary certificate.

debian
больше 11 лет назад

PyWBEM 0.7 and earlier uses a separate connection to validate X.509 ce ...

EPSS

Процентиль: 57%
0.00345
Низкий

8.7 High

CVSS4

7.5 High

CVSS3

Дефекты

CWE-20