Lucene search

K
githubGitHub Advisory DatabaseGHSA-Q48Q-77QV-CF9P
HistoryMay 14, 2022 - 1:52 a.m.

httplib2 incorrectly checks SSL certificate

2022-05-1401:52:01
CWE-20
GitHub Advisory Database
github.com
5

2.6 Low

CVSS2

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:H/Au:N/C:N/I:P/A:N

6.5 Medium

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

52.9%

httplib2 prior to version 0.10.1, after an initial connection is made, does not verify that the server hostname matches a domain name in the subject’s Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.

Affected configurations

Vulners
Node
httplib2httplib2Range<0.10.1
CPENameOperatorVersion
httplib2lt0.10.1

2.6 Low

CVSS2

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:H/Au:N/C:N/I:P/A:N

6.5 Medium

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

52.9%