Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:13658
HistoryApr 22, 2019 - 3:35 a.m.

SSL Hostname Verification Bypass

2019-04-2203:35:22
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
6

0.004 Low

EPSS

Percentile

74.4%

urllib3 is vulnerable to SSL Hostname verification bypass. The vulnerability exists as urllib3 incorrectly loads system certificates even when an explicit set of CA certificates were specified, possibly allowing man-in-the-middle attacks.