Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-2996

Опубликовано: 01 июн. 2022
Источник: redhat
CVSS3: 7.4
EPSS Низкий

Описание

A flaw was found in the python-scciclient when making an HTTPS connection to a server where the server's certificate would not be verified. This issue opens up the connection to possible Man-in-the-middle (MITM) attacks.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat OpenStack Platform 13 (Queens)python-scciclientOut of support scope
Ironic content for Red Hat OpenShift Container Platform 4.12crudiniFixedRHSA-2022:739817.01.2023
Ironic content for Red Hat OpenShift Container Platform 4.12futureFixedRHSA-2022:739817.01.2023
Ironic content for Red Hat OpenShift Container Platform 4.12openstack-ironicFixedRHSA-2022:739817.01.2023
Ironic content for Red Hat OpenShift Container Platform 4.12openstack-ironic-inspectorFixedRHSA-2022:739817.01.2023
Ironic content for Red Hat OpenShift Container Platform 4.12openstack-ironic-python-agentFixedRHSA-2022:739817.01.2023
Ironic content for Red Hat OpenShift Container Platform 4.12openstack-macrosFixedRHSA-2022:739817.01.2023
Ironic content for Red Hat OpenShift Container Platform 4.12pyflakesFixedRHSA-2022:739817.01.2023
Ironic content for Red Hat OpenShift Container Platform 4.12pyOpenSSLFixedRHSA-2022:739817.01.2023
Ironic content for Red Hat OpenShift Container Platform 4.12pysnmpFixedRHSA-2022:739817.01.2023

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-295
https://bugzilla.redhat.com/show_bug.cgi?id=2115122python-scciclient: missing server certificate verification

EPSS

Процентиль: 41%
0.00194
Низкий

7.4 High

CVSS3

Связанные уязвимости

CVSS3: 7.4
ubuntu
больше 3 лет назад

A flaw was found in the python-scciclient when making an HTTPS connection to a server where the server's certificate would not be verified. This issue opens up the connection to possible Man-in-the-middle (MITM) attacks.

CVSS3: 7.4
nvd
больше 3 лет назад

A flaw was found in the python-scciclient when making an HTTPS connection to a server where the server's certificate would not be verified. This issue opens up the connection to possible Man-in-the-middle (MITM) attacks.

CVSS3: 7.4
debian
больше 3 лет назад

A flaw was found in the python-scciclient when making an HTTPS connect ...

CVSS3: 7.4
github
больше 3 лет назад

python-scciclient vulnerable to Man-in-the-middle (MITM) attacks

EPSS

Процентиль: 41%
0.00194
Низкий

7.4 High

CVSS3