Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-v6fx-m8cj-52v3

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 5.9

Описание

The ssl.match_hostname function in CPython (aka Python) before 2.7.9 and 3.x before 3.3.3 does not properly handle wildcards in hostnames, which might allow man-in-the-middle attackers to spoof servers via a crafted certificate.

The ssl.match_hostname function in CPython (aka Python) before 2.7.9 and 3.x before 3.3.3 does not properly handle wildcards in hostnames, which might allow man-in-the-middle attackers to spoof servers via a crafted certificate.

EPSS

Процентиль: 67%
0.00557
Низкий

5.9 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.9
ubuntu
около 9 лет назад

The ssl.match_hostname function in CPython (aka Python) before 2.7.9 and 3.x before 3.3.3 does not properly handle wildcards in hostnames, which might allow man-in-the-middle attackers to spoof servers via a crafted certificate.

redhat
почти 12 лет назад

The ssl.match_hostname function in CPython (aka Python) before 2.7.9 and 3.x before 3.3.3 does not properly handle wildcards in hostnames, which might allow man-in-the-middle attackers to spoof servers via a crafted certificate.

CVSS3: 5.9
nvd
около 9 лет назад

The ssl.match_hostname function in CPython (aka Python) before 2.7.9 and 3.x before 3.3.3 does not properly handle wildcards in hostnames, which might allow man-in-the-middle attackers to spoof servers via a crafted certificate.

CVSS3: 5.9
debian
около 9 лет назад

The ssl.match_hostname function in CPython (aka Python) before 2.7.9 a ...

suse-cvrf
почти 10 лет назад

Recommended update for python-setuptools

EPSS

Процентиль: 67%
0.00557
Низкий

5.9 Medium

CVSS3