Vulnerabilities
Vulnerable Software
Python:  >> Urllib3  >> 1.24  Security Vulnerabilities
The urllib3 library before 1.24.2 for Python mishandles certain cases where the desired set of CA certificates is different from the OS store of CA certificates, which results in SSL connections succeeding in situations where a verification failure is the correct outcome. This is related to use of the ssl_context, ca_certs, or ca_certs_dir argument.
CVSS Score
7.5
EPSS Score
0.01
Published
2019-04-18
In the urllib3 library through 1.24.1 for Python, CRLF injection is possible if the attacker controls the request parameter.
CVSS Score
6.1
EPSS Score
0.006
Published
2019-04-15


Contact Us

Shodan ® - All rights reserved