Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-rf3f-3p37-2qh4

Опубликовано: 02 сент. 2022
Источник: github
Github: Прошло ревью
CVSS4: 9.1
CVSS3: 7.4

Описание

python-scciclient vulnerable to Man-in-the-middle (MITM) attacks

A flaw was found in the python-scciclient when making an HTTPS connection to a server where the server's certificate would not be verified. This issue opens up the connection to possible Man-in-the-middle (MITM) attacks.

Пакеты

Наименование

python-scciclient

pip
Затронутые версииВерсия исправления

< 0.12.0

0.12.0

EPSS

Процентиль: 41%
0.00194
Низкий

9.1 Critical

CVSS4

7.4 High

CVSS3

Дефекты

CWE-295

Связанные уязвимости

CVSS3: 7.4
ubuntu
больше 3 лет назад

A flaw was found in the python-scciclient when making an HTTPS connection to a server where the server's certificate would not be verified. This issue opens up the connection to possible Man-in-the-middle (MITM) attacks.

CVSS3: 7.4
redhat
больше 3 лет назад

A flaw was found in the python-scciclient when making an HTTPS connection to a server where the server's certificate would not be verified. This issue opens up the connection to possible Man-in-the-middle (MITM) attacks.

CVSS3: 7.4
nvd
больше 3 лет назад

A flaw was found in the python-scciclient when making an HTTPS connection to a server where the server's certificate would not be verified. This issue opens up the connection to possible Man-in-the-middle (MITM) attacks.

CVSS3: 7.4
debian
больше 3 лет назад

A flaw was found in the python-scciclient when making an HTTPS connect ...

EPSS

Процентиль: 41%
0.00194
Низкий

9.1 Critical

CVSS4

7.4 High

CVSS3

Дефекты

CWE-295