Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:29711
HistoryMar 16, 2021 - 4:13 a.m.

Man-in-the-Middle (MitM)

2021-03-1604:13:16
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
15
urllib3
ssl certificate
validation
https
proxies
hostname verification

EPSS

0.001

Percentile

49.3%

urllib3 is vulnerable to man-in-the-middle attack. The SSL certificate validation is omitted in certain HTTPS to HTTPS proxies. When an SSL Context is not given via proxy_config, the hostname of the certificate is not verified in the initial connection.