Логотип exploitDog
bind:"CVE-2018-20060" OR bind:"CVE-2019-11324" OR bind:"CVE-2018-18074" OR bind:"CVE-2019-11236"
Консоль
Логотип exploitDog

exploitDog

bind:"CVE-2018-20060" OR bind:"CVE-2019-11324" OR bind:"CVE-2018-18074" OR bind:"CVE-2019-11236"

Количество 48

Количество 48

oracle-oval логотип

ELSA-2019-3335

около 6 лет назад

ELSA-2019-3335: python27:2.7 security and bug fix update (MODERATE)

EPSS: Низкий
ubuntu логотип

CVE-2019-11324

почти 7 лет назад

The urllib3 library before 1.24.2 for Python mishandles certain cases where the desired set of CA certificates is different from the OS store of CA certificates, which results in SSL connections succeeding in situations where a verification failure is the correct outcome. This is related to use of the ssl_context, ca_certs, or ca_certs_dir argument.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2019-11324

почти 7 лет назад

The urllib3 library before 1.24.2 for Python mishandles certain cases where the desired set of CA certificates is different from the OS store of CA certificates, which results in SSL connections succeeding in situations where a verification failure is the correct outcome. This is related to use of the ssl_context, ca_certs, or ca_certs_dir argument.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2019-11324

почти 7 лет назад

The urllib3 library before 1.24.2 for Python mishandles certain cases where the desired set of CA certificates is different from the OS store of CA certificates, which results in SSL connections succeeding in situations where a verification failure is the correct outcome. This is related to use of the ssl_context, ca_certs, or ca_certs_dir argument.

CVSS3: 7.5
EPSS: Низкий
msrc логотип

CVE-2019-11324

5 месяцев назад

The urllib3 library before 1.24.2 for Python mishandles certain cases where the desired set of CA certificates is different from the OS store of CA certificates, which results in SSL connections succeeding in situations where a verification failure is the correct outcome. This is related to use of the ssl_context, ca_certs, or ca_certs_dir argument.

EPSS: Низкий
debian логотип

CVE-2019-11324

почти 7 лет назад

The urllib3 library before 1.24.2 for Python mishandles certain cases ...

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-mh33-7rrq-662w

почти 7 лет назад

Improper Certificate Validation in urllib3

CVSS3: 7.5
EPSS: Низкий
fstec логотип

BDU:2019-02105

почти 7 лет назад

Уязвимость модуля urllib3 интерпретатора языка программирования Python, связанная с ошибками процедуры подтверждения подлинности сертификата, позволяющая нарушителю установить SSL-соединение

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2018-18074

больше 7 лет назад

The Requests package before 2.20.0 for Python sends an HTTP Authorization header to an http URI upon receiving a same-hostname https-to-http redirect, which makes it easier for remote attackers to discover credentials by sniffing the network.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2018-18074

больше 7 лет назад

The Requests package before 2.20.0 for Python sends an HTTP Authorization header to an http URI upon receiving a same-hostname https-to-http redirect, which makes it easier for remote attackers to discover credentials by sniffing the network.

CVSS3: 2.6
EPSS: Низкий
nvd логотип

CVE-2018-18074

больше 7 лет назад

The Requests package before 2.20.0 for Python sends an HTTP Authorization header to an http URI upon receiving a same-hostname https-to-http redirect, which makes it easier for remote attackers to discover credentials by sniffing the network.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2018-18074

больше 7 лет назад

The Requests package before 2.20.0 for Python sends an HTTP Authorizat ...

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2019-11236

почти 7 лет назад

In the urllib3 library through 1.24.1 for Python, CRLF injection is possible if the attacker controls the request parameter.

CVSS3: 6.1
EPSS: Низкий
redhat логотип

CVE-2019-11236

почти 7 лет назад

In the urllib3 library through 1.24.1 for Python, CRLF injection is possible if the attacker controls the request parameter.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2019-11236

почти 7 лет назад

In the urllib3 library through 1.24.1 for Python, CRLF injection is possible if the attacker controls the request parameter.

CVSS3: 6.1
EPSS: Низкий
msrc логотип

CVE-2019-11236

около 5 лет назад

In the urllib3 library through 1.24.1 for Python CRLF injection is possible if the attacker controls the request parameter.

CVSS3: 6.1
EPSS: Низкий
debian логотип

CVE-2019-11236

почти 7 лет назад

In the urllib3 library through 1.24.1 for Python, CRLF injection is po ...

CVSS3: 6.1
EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2019:1754-1

больше 6 лет назад

Security update for python-requests

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2022:1819-1

больше 3 лет назад

Security update for python-requests

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2022:1448-1

почти 4 года назад

Security update for python-requests

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
oracle-oval логотип
ELSA-2019-3335

ELSA-2019-3335: python27:2.7 security and bug fix update (MODERATE)

около 6 лет назад
ubuntu логотип
CVE-2019-11324

The urllib3 library before 1.24.2 for Python mishandles certain cases where the desired set of CA certificates is different from the OS store of CA certificates, which results in SSL connections succeeding in situations where a verification failure is the correct outcome. This is related to use of the ssl_context, ca_certs, or ca_certs_dir argument.

CVSS3: 7.5
1%
Низкий
почти 7 лет назад
redhat логотип
CVE-2019-11324

The urllib3 library before 1.24.2 for Python mishandles certain cases where the desired set of CA certificates is different from the OS store of CA certificates, which results in SSL connections succeeding in situations where a verification failure is the correct outcome. This is related to use of the ssl_context, ca_certs, or ca_certs_dir argument.

CVSS3: 7.5
1%
Низкий
почти 7 лет назад
nvd логотип
CVE-2019-11324

The urllib3 library before 1.24.2 for Python mishandles certain cases where the desired set of CA certificates is different from the OS store of CA certificates, which results in SSL connections succeeding in situations where a verification failure is the correct outcome. This is related to use of the ssl_context, ca_certs, or ca_certs_dir argument.

CVSS3: 7.5
1%
Низкий
почти 7 лет назад
msrc логотип
CVE-2019-11324

The urllib3 library before 1.24.2 for Python mishandles certain cases where the desired set of CA certificates is different from the OS store of CA certificates, which results in SSL connections succeeding in situations where a verification failure is the correct outcome. This is related to use of the ssl_context, ca_certs, or ca_certs_dir argument.

1%
Низкий
5 месяцев назад
debian логотип
CVE-2019-11324

The urllib3 library before 1.24.2 for Python mishandles certain cases ...

CVSS3: 7.5
1%
Низкий
почти 7 лет назад
github логотип
GHSA-mh33-7rrq-662w

Improper Certificate Validation in urllib3

CVSS3: 7.5
1%
Низкий
почти 7 лет назад
fstec логотип
BDU:2019-02105

Уязвимость модуля urllib3 интерпретатора языка программирования Python, связанная с ошибками процедуры подтверждения подлинности сертификата, позволяющая нарушителю установить SSL-соединение

CVSS3: 7.5
1%
Низкий
почти 7 лет назад
ubuntu логотип
CVE-2018-18074

The Requests package before 2.20.0 for Python sends an HTTP Authorization header to an http URI upon receiving a same-hostname https-to-http redirect, which makes it easier for remote attackers to discover credentials by sniffing the network.

CVSS3: 7.5
0%
Низкий
больше 7 лет назад
redhat логотип
CVE-2018-18074

The Requests package before 2.20.0 for Python sends an HTTP Authorization header to an http URI upon receiving a same-hostname https-to-http redirect, which makes it easier for remote attackers to discover credentials by sniffing the network.

CVSS3: 2.6
0%
Низкий
больше 7 лет назад
nvd логотип
CVE-2018-18074

The Requests package before 2.20.0 for Python sends an HTTP Authorization header to an http URI upon receiving a same-hostname https-to-http redirect, which makes it easier for remote attackers to discover credentials by sniffing the network.

CVSS3: 7.5
0%
Низкий
больше 7 лет назад
debian логотип
CVE-2018-18074

The Requests package before 2.20.0 for Python sends an HTTP Authorizat ...

CVSS3: 7.5
0%
Низкий
больше 7 лет назад
ubuntu логотип
CVE-2019-11236

In the urllib3 library through 1.24.1 for Python, CRLF injection is possible if the attacker controls the request parameter.

CVSS3: 6.1
1%
Низкий
почти 7 лет назад
redhat логотип
CVE-2019-11236

In the urllib3 library through 1.24.1 for Python, CRLF injection is possible if the attacker controls the request parameter.

CVSS3: 6.5
1%
Низкий
почти 7 лет назад
nvd логотип
CVE-2019-11236

In the urllib3 library through 1.24.1 for Python, CRLF injection is possible if the attacker controls the request parameter.

CVSS3: 6.1
1%
Низкий
почти 7 лет назад
msrc логотип
CVE-2019-11236

In the urllib3 library through 1.24.1 for Python CRLF injection is possible if the attacker controls the request parameter.

CVSS3: 6.1
1%
Низкий
около 5 лет назад
debian логотип
CVE-2019-11236

In the urllib3 library through 1.24.1 for Python, CRLF injection is po ...

CVSS3: 6.1
1%
Низкий
почти 7 лет назад
suse-cvrf логотип
openSUSE-SU-2019:1754-1

Security update for python-requests

0%
Низкий
больше 6 лет назад
suse-cvrf логотип
SUSE-SU-2022:1819-1

Security update for python-requests

0%
Низкий
больше 3 лет назад
suse-cvrf логотип
SUSE-SU-2022:1448-1

Security update for python-requests

0%
Низкий
почти 4 года назад

Уязвимостей на страницу