Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-g8h3-j4r4-m45r

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The _ssl_verify_callback function in tls_nb.py in Gajim before 0.15.3 does not properly verify SSL certificates, which allows remote attackers to conduct man-in-the-middle (MITM) attacks and spoof servers via an arbitrary certificate from a trusted CA.

The _ssl_verify_callback function in tls_nb.py in Gajim before 0.15.3 does not properly verify SSL certificates, which allows remote attackers to conduct man-in-the-middle (MITM) attacks and spoof servers via an arbitrary certificate from a trusted CA.

EPSS

Процентиль: 42%
0.00203
Низкий

Дефекты

CWE-20

Связанные уязвимости

ubuntu
около 12 лет назад

The _ssl_verify_callback function in tls_nb.py in Gajim before 0.15.3 does not properly verify SSL certificates, which allows remote attackers to conduct man-in-the-middle (MITM) attacks and spoof servers via an arbitrary certificate from a trusted CA.

nvd
около 12 лет назад

The _ssl_verify_callback function in tls_nb.py in Gajim before 0.15.3 does not properly verify SSL certificates, which allows remote attackers to conduct man-in-the-middle (MITM) attacks and spoof servers via an arbitrary certificate from a trusted CA.

debian
около 12 лет назад

The _ssl_verify_callback function in tls_nb.py in Gajim before 0.15.3 ...

EPSS

Процентиль: 42%
0.00203
Низкий

Дефекты

CWE-20