Описание
Restkit Does Not Validate TLS certificates
Restkit allows man-in-the-middle attackers to spoof TLS servers by leveraging use of the ssl.wrap_socket function in Python with the default CERT_NONE value for the cert_reqs argument.
Пакеты
Наименование
restkit
pip
Затронутые версииВерсия исправления
<= 4.2.2
Отсутствует
Связанные уязвимости
CVSS3: 5.9
ubuntu
больше 8 лет назад
Restkit allows man-in-the-middle attackers to spoof TLS servers by leveraging use of the ssl.wrap_socket function in Python with the default CERT_NONE value for the cert_reqs argument.
CVSS3: 5.9
nvd
больше 8 лет назад
Restkit allows man-in-the-middle attackers to spoof TLS servers by leveraging use of the ssl.wrap_socket function in Python with the default CERT_NONE value for the cert_reqs argument.
CVSS3: 5.9
debian
больше 8 лет назад
Restkit allows man-in-the-middle attackers to spoof TLS servers by lev ...