Ecosyste.ms: Advisories

An open API service providing security vulnerability metadata for many open source software ecosystems.

Security Advisories: GSA_kwCzR0hTQS1xNDhxLTc3cXYtY2Y5cM4AAUp3

httplib2 incorrectly checks SSL certificate

httplib2 prior to version 0.10.1, after an initial connection is made, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.

Permalink: https://github.com/advisories/GHSA-q48q-77qv-cf9p
JSON: https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1xNDhxLTc3cXYtY2Y5cM4AAUp3
Source: GitHub Advisory Database
Origin: Unspecified
Severity: Low
Classification: General
Published: about 2 years ago
Updated: 17 days ago


Identifiers: GHSA-q48q-77qv-cf9p, CVE-2013-2037
References: Repository: https://github.com/httplib2/httplib2
Blast Radius: 0.0

Affected Packages

pypi:httplib2
Dependent packages: 266
Dependent repositories: 48,310
Downloads: 41,633,749 last month
Affected Version Ranges: < 0.10.1
Fixed in: 0.10.1
All affected versions: 0.7.0, 0.7.1, 0.7.2, 0.7.3, 0.7.4, 0.7.5, 0.7.6, 0.7.7, 0.9.1, 0.9.2
All unaffected versions: 0.10.3, 0.11.0, 0.11.1, 0.11.3, 0.12.0, 0.12.1, 0.12.3, 0.13.0, 0.13.1, 0.14.0, 0.15.0, 0.16.0, 0.17.0, 0.17.1, 0.17.2, 0.17.3, 0.17.4, 0.18.0, 0.18.1, 0.19.0, 0.19.1, 0.20.0, 0.20.1, 0.20.2, 0.20.4, 0.21.0, 0.22.0