Lucene search

K
osvGoogleOSV:GHSA-5PHF-PP7P-VC2R
HistoryMar 19, 2021 - 7:42 p.m.

Using default SSLContext for HTTPS requests in an HTTPS proxy doesn't verify certificate hostname for proxy connection

2021-03-1919:42:11
Google
osv.dev
38

0.001 Low

EPSS

Percentile

49.4%

Impact

Users who are using an HTTPS proxy to issue HTTPS requests and haven’t configured their own SSLContext via proxy_config.
Only the default SSLContext is impacted.

Patches

urllib3 >=1.26.4 has the issue resolved. urllib3<1.26 is not impacted due to not supporting HTTPS requests via HTTPS proxies.

Workarounds

Upgrading is recommended as this is a minor release and not likely to break current usage.

Configuring an SSLContext with check_hostname=True and passing via proxy_config instead of relying on the default SSLContext

For more information

If you have any questions or comments about this advisory: