Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2019-11324

Опубликовано: 18 апр. 2019
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 5
CVSS3: 7.5

Описание

The urllib3 library before 1.24.2 for Python mishandles certain cases where the desired set of CA certificates is different from the OS store of CA certificates, which results in SSL connections succeeding in situations where a verification failure is the correct outcome. This is related to use of the ssl_context, ca_certs, or ca_certs_dir argument.

РелизСтатусПримечание
bionic

released

1.22-1ubuntu0.18.04.1
cosmic

released

1.22-1ubuntu0.18.10.1
devel

released

1.24.1-1ubuntu1
disco

released

1.24.1-1ubuntu0.1
esm-infra-legacy/trusty

not-affected

code not present
esm-infra/bionic

not-affected

1.22-1ubuntu0.18.04.1
esm-infra/xenial

not-affected

code not present
precise/esm

DNE

trusty

ignored

end of standard support
trusty/esm

not-affected

code not present

Показывать по

EPSS

Процентиль: 79%
0.01379
Низкий

5 Medium

CVSS2

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
redhat
около 6 лет назад

The urllib3 library before 1.24.2 for Python mishandles certain cases where the desired set of CA certificates is different from the OS store of CA certificates, which results in SSL connections succeeding in situations where a verification failure is the correct outcome. This is related to use of the ssl_context, ca_certs, or ca_certs_dir argument.

CVSS3: 7.5
nvd
около 6 лет назад

The urllib3 library before 1.24.2 for Python mishandles certain cases where the desired set of CA certificates is different from the OS store of CA certificates, which results in SSL connections succeeding in situations where a verification failure is the correct outcome. This is related to use of the ssl_context, ca_certs, or ca_certs_dir argument.

CVSS3: 7.5
debian
около 6 лет назад

The urllib3 library before 1.24.2 for Python mishandles certain cases ...

CVSS3: 7.5
github
около 6 лет назад

Improper Certificate Validation in urllib3

CVSS3: 7.5
fstec
около 6 лет назад

Уязвимость модуля urllib3 интерпретатора языка программирования Python, связанная с ошибками процедуры подтверждения подлинности сертификата, позволяющая нарушителю установить SSL-соединение

EPSS

Процентиль: 79%
0.01379
Низкий

5 Medium

CVSS2

7.5 High

CVSS3