Описание
Restkit allows man-in-the-middle attackers to spoof TLS servers by leveraging use of the ssl.wrap_socket function in Python with the default CERT_NONE value for the cert_reqs argument.
Ссылки
- Mailing ListVDB Entry
- Issue TrackingThird Party AdvisoryVDB Entry
- Third Party Advisory
- Mailing ListVDB Entry
- Issue TrackingThird Party AdvisoryVDB Entry
- Third Party Advisory
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:restkit:restkit:-:*:*:*:*:*:*:*
EPSS
Процентиль: 56%
0.0034
Низкий
5.9 Medium
CVSS3
4.3 Medium
CVSS2
Дефекты
CWE-295
Связанные уязвимости
CVSS3: 5.9
ubuntu
больше 8 лет назад
Restkit allows man-in-the-middle attackers to spoof TLS servers by leveraging use of the ssl.wrap_socket function in Python with the default CERT_NONE value for the cert_reqs argument.
CVSS3: 5.9
debian
больше 8 лет назад
Restkit allows man-in-the-middle attackers to spoof TLS servers by lev ...
EPSS
Процентиль: 56%
0.0034
Низкий
5.9 Medium
CVSS3
4.3 Medium
CVSS2
Дефекты
CWE-295