EIQ-2019-0022
ID |
EIQ-2019-0022 |
CVE |
|
Description |
SSL connection with improper authentication in urllib3 versions 1.24.1 and earlier |
Date |
22 Apr 2019 |
Severity |
3 - HIGH |
CVSSv3 score |
7.5 |
Status |
2.4.0 |
Assessment |
The CA certificate handler component in the urllib3 library versions 1.24.1 and earlier incorrectly handles cases when the desired CA certificates do not match the corresponding CA certificates in the system certificate store. Because of weak/improper authentication, it could be possible to initiate a SSL connection, when it would normally not be allowed because of verification failure. An attacker could exploit this vulnerability by manipulating the ssl_context, ca_certs, or ca_certs_dir arguments with unknown input. |
Mitigation |
Upgrade urllib3 to version 1.24.2 or later. |
Affected versions |
2.3.4 and earlier. |
Notes |
For more information, see: |
< Back to all security issues and mitigation actions
In release notes 2.4.0