Lucene search

K
cvelistMitreCVELIST:CVE-2014-9365
HistoryDec 12, 2014 - 11:00 a.m.

CVE-2014-9365

2014-12-1211:00:00
mitre
www.cve.org
1

7.3 High

AI Score

Confidence

High

0.006 Low

EPSS

Percentile

77.9%

The HTTP clients in the (1) httplib, (2) urllib, (3) urllib2, and (4) xmlrpclib libraries in CPython (aka Python) 2.x before 2.7.9 and 3.x before 3.4.3, when accessing an HTTPS URL, do not (a) check the certificate against a trust store or verify that the server hostname matches a domain name in the subject’s (b) Common Name or © subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.