Логотип exploitDog
bind:"GHSA-4j9r-82g6-9mj3" OR bind:"CVE-2023-40217"
Консоль
Логотип exploitDog

exploitDog

bind:"GHSA-4j9r-82g6-9mj3" OR bind:"CVE-2023-40217"

Количество 29

Количество 29

github логотип

GHSA-4j9r-82g6-9mj3

почти 2 года назад

An issue was discovered in Python before 3.8.18, 3.9.x before 3.9.18, 3.10.x before 3.10.13, and 3.11.x before 3.11.5. It primarily affects servers (such as HTTP servers) that use TLS client authentication. If a TLS server-side socket is created, receives data into the socket buffer, and then is closed quickly, there is a brief window where the SSLSocket instance will detect the socket as "not connected" and won't initiate a handshake, but buffered data will still be readable from the socket buffer. This data will not be authenticated if the server-side TLS peer is expecting client certificate authentication, and is indistinguishable from valid TLS stream data. Data is limited in size to the amount that will fit in the buffer. (The TLS connection cannot directly be used for data exfiltration because the vulnerable code path requires that the connection be closed on initialization of the SSLSocket.)

CVSS3: 5.3
EPSS: Низкий
ubuntu логотип

CVE-2023-40217

почти 2 года назад

An issue was discovered in Python before 3.8.18, 3.9.x before 3.9.18, 3.10.x before 3.10.13, and 3.11.x before 3.11.5. It primarily affects servers (such as HTTP servers) that use TLS client authentication. If a TLS server-side socket is created, receives data into the socket buffer, and then is closed quickly, there is a brief window where the SSLSocket instance will detect the socket as "not connected" and won't initiate a handshake, but buffered data will still be readable from the socket buffer. This data will not be authenticated if the server-side TLS peer is expecting client certificate authentication, and is indistinguishable from valid TLS stream data. Data is limited in size to the amount that will fit in the buffer. (The TLS connection cannot directly be used for data exfiltration because the vulnerable code path requires that the connection be closed on initialization of the SSLSocket.)

CVSS3: 5.3
EPSS: Низкий
redhat логотип

CVE-2023-40217

почти 2 года назад

An issue was discovered in Python before 3.8.18, 3.9.x before 3.9.18, 3.10.x before 3.10.13, and 3.11.x before 3.11.5. It primarily affects servers (such as HTTP servers) that use TLS client authentication. If a TLS server-side socket is created, receives data into the socket buffer, and then is closed quickly, there is a brief window where the SSLSocket instance will detect the socket as "not connected" and won't initiate a handshake, but buffered data will still be readable from the socket buffer. This data will not be authenticated if the server-side TLS peer is expecting client certificate authentication, and is indistinguishable from valid TLS stream data. Data is limited in size to the amount that will fit in the buffer. (The TLS connection cannot directly be used for data exfiltration because the vulnerable code path requires that the connection be closed on initialization of the SSLSocket.)

CVSS3: 8.6
EPSS: Низкий
nvd логотип

CVE-2023-40217

почти 2 года назад

An issue was discovered in Python before 3.8.18, 3.9.x before 3.9.18, 3.10.x before 3.10.13, and 3.11.x before 3.11.5. It primarily affects servers (such as HTTP servers) that use TLS client authentication. If a TLS server-side socket is created, receives data into the socket buffer, and then is closed quickly, there is a brief window where the SSLSocket instance will detect the socket as "not connected" and won't initiate a handshake, but buffered data will still be readable from the socket buffer. This data will not be authenticated if the server-side TLS peer is expecting client certificate authentication, and is indistinguishable from valid TLS stream data. Data is limited in size to the amount that will fit in the buffer. (The TLS connection cannot directly be used for data exfiltration because the vulnerable code path requires that the connection be closed on initialization of the SSLSocket.)

CVSS3: 5.3
EPSS: Низкий
msrc логотип

CVE-2023-40217

больше 1 года назад

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2023-40217

почти 2 года назад

An issue was discovered in Python before 3.8.18, 3.9.x before 3.9.18, ...

CVSS3: 5.3
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2023:3933-1

больше 1 года назад

Security update for python

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2023:3828-1

больше 1 года назад

Security update for python3

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2023:3824-1

больше 1 года назад

Security update for python310

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2023:3804-1

больше 1 года назад

Security update for python3

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2023:3731-1

больше 1 года назад

Security update for python36

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2023:3730-1

больше 1 года назад

Security update for python

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2023:3708-1

больше 1 года назад

Security update for python39

EPSS: Низкий
rocky логотип

RLSA-2023:5997

больше 1 года назад

Important: python3 security update

EPSS: Низкий
rocky логотип

RLSA-2023:5463

больше 1 года назад

Important: python3.11 security update

EPSS: Низкий
oracle-oval логотип

ELSA-2023-6885

больше 1 года назад

ELSA-2023-6885: python security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2023-6823

больше 1 года назад

ELSA-2023-6823: python3 security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2023-5998

больше 1 года назад

ELSA-2023-5998: python39:3.9 and python39-devel:3.9 security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2023-5997

больше 1 года назад

ELSA-2023-5997: python3 security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2023-5994

больше 1 года назад

ELSA-2023-5994: python27:2.7 security update (IMPORTANT)

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-4j9r-82g6-9mj3

An issue was discovered in Python before 3.8.18, 3.9.x before 3.9.18, 3.10.x before 3.10.13, and 3.11.x before 3.11.5. It primarily affects servers (such as HTTP servers) that use TLS client authentication. If a TLS server-side socket is created, receives data into the socket buffer, and then is closed quickly, there is a brief window where the SSLSocket instance will detect the socket as "not connected" and won't initiate a handshake, but buffered data will still be readable from the socket buffer. This data will not be authenticated if the server-side TLS peer is expecting client certificate authentication, and is indistinguishable from valid TLS stream data. Data is limited in size to the amount that will fit in the buffer. (The TLS connection cannot directly be used for data exfiltration because the vulnerable code path requires that the connection be closed on initialization of the SSLSocket.)

CVSS3: 5.3
0%
Низкий
почти 2 года назад
ubuntu логотип
CVE-2023-40217

An issue was discovered in Python before 3.8.18, 3.9.x before 3.9.18, 3.10.x before 3.10.13, and 3.11.x before 3.11.5. It primarily affects servers (such as HTTP servers) that use TLS client authentication. If a TLS server-side socket is created, receives data into the socket buffer, and then is closed quickly, there is a brief window where the SSLSocket instance will detect the socket as "not connected" and won't initiate a handshake, but buffered data will still be readable from the socket buffer. This data will not be authenticated if the server-side TLS peer is expecting client certificate authentication, and is indistinguishable from valid TLS stream data. Data is limited in size to the amount that will fit in the buffer. (The TLS connection cannot directly be used for data exfiltration because the vulnerable code path requires that the connection be closed on initialization of the SSLSocket.)

CVSS3: 5.3
0%
Низкий
почти 2 года назад
redhat логотип
CVE-2023-40217

An issue was discovered in Python before 3.8.18, 3.9.x before 3.9.18, 3.10.x before 3.10.13, and 3.11.x before 3.11.5. It primarily affects servers (such as HTTP servers) that use TLS client authentication. If a TLS server-side socket is created, receives data into the socket buffer, and then is closed quickly, there is a brief window where the SSLSocket instance will detect the socket as "not connected" and won't initiate a handshake, but buffered data will still be readable from the socket buffer. This data will not be authenticated if the server-side TLS peer is expecting client certificate authentication, and is indistinguishable from valid TLS stream data. Data is limited in size to the amount that will fit in the buffer. (The TLS connection cannot directly be used for data exfiltration because the vulnerable code path requires that the connection be closed on initialization of the SSLSocket.)

CVSS3: 8.6
0%
Низкий
почти 2 года назад
nvd логотип
CVE-2023-40217

An issue was discovered in Python before 3.8.18, 3.9.x before 3.9.18, 3.10.x before 3.10.13, and 3.11.x before 3.11.5. It primarily affects servers (such as HTTP servers) that use TLS client authentication. If a TLS server-side socket is created, receives data into the socket buffer, and then is closed quickly, there is a brief window where the SSLSocket instance will detect the socket as "not connected" and won't initiate a handshake, but buffered data will still be readable from the socket buffer. This data will not be authenticated if the server-side TLS peer is expecting client certificate authentication, and is indistinguishable from valid TLS stream data. Data is limited in size to the amount that will fit in the buffer. (The TLS connection cannot directly be used for data exfiltration because the vulnerable code path requires that the connection be closed on initialization of the SSLSocket.)

CVSS3: 5.3
0%
Низкий
почти 2 года назад
msrc логотип
CVSS3: 5.3
0%
Низкий
больше 1 года назад
debian логотип
CVE-2023-40217

An issue was discovered in Python before 3.8.18, 3.9.x before 3.9.18, ...

CVSS3: 5.3
0%
Низкий
почти 2 года назад
suse-cvrf логотип
SUSE-SU-2023:3933-1

Security update for python

0%
Низкий
больше 1 года назад
suse-cvrf логотип
SUSE-SU-2023:3828-1

Security update for python3

0%
Низкий
больше 1 года назад
suse-cvrf логотип
SUSE-SU-2023:3824-1

Security update for python310

0%
Низкий
больше 1 года назад
suse-cvrf логотип
SUSE-SU-2023:3804-1

Security update for python3

0%
Низкий
больше 1 года назад
suse-cvrf логотип
SUSE-SU-2023:3731-1

Security update for python36

0%
Низкий
больше 1 года назад
suse-cvrf логотип
SUSE-SU-2023:3730-1

Security update for python

0%
Низкий
больше 1 года назад
suse-cvrf логотип
SUSE-SU-2023:3708-1

Security update for python39

0%
Низкий
больше 1 года назад
rocky логотип
RLSA-2023:5997

Important: python3 security update

0%
Низкий
больше 1 года назад
rocky логотип
RLSA-2023:5463

Important: python3.11 security update

0%
Низкий
больше 1 года назад
oracle-oval логотип
ELSA-2023-6885

ELSA-2023-6885: python security update (IMPORTANT)

больше 1 года назад
oracle-oval логотип
ELSA-2023-6823

ELSA-2023-6823: python3 security update (IMPORTANT)

больше 1 года назад
oracle-oval логотип
ELSA-2023-5998

ELSA-2023-5998: python39:3.9 and python39-devel:3.9 security update (IMPORTANT)

больше 1 года назад
oracle-oval логотип
ELSA-2023-5997

ELSA-2023-5997: python3 security update (IMPORTANT)

больше 1 года назад
oracle-oval логотип
ELSA-2023-5994

ELSA-2023-5994: python27:2.7 security update (IMPORTANT)

больше 1 года назад

Уязвимостей на страницу