CVE-2016-9015 Detail
Current Description
Versions 1.17 and 1.18 of the Python urllib3 library suffer from a vulnerability that can cause them, in certain configurations, to not correctly validate TLS certificates. This places users of the library with those configurations at risk of man-in-the-middle and information leakage attacks. This vulnerability affects users using versions 1.17 and 1.18 of the urllib3 library, who are using the optional PyOpenSSL support for TLS instead of the regular standard library TLS backend, and who are using OpenSSL 1.1.0 via PyOpenSSL. This is an extremely uncommon configuration, so the security impact of this vulnerability is low.
Source:
MITRE
View Analysis Description
Analysis Description
Versions 1.17 and 1.18 of the Python urllib3 library suffer from a vulnerability that can cause them, in certain configurations, to not correctly validate TLS certificates. This places users of the library with those configurations at risk of man-in-the-middle and information leakage attacks. This vulnerability affects users using versions 1.17 and 1.18 of the urllib3 library, who are using the optional PyOpenSSL support for TLS instead of the regular standard library TLS backend, and who are using OpenSSL 1.1.0 via PyOpenSSL. This is an extremely uncommon configuration, so the security impact of this vulnerability is low.
Source:
MITRE
Severity
CVSS 3.x Severity and Metrics:
Vector: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
CVSS 2.0 Severity and Metrics:
Vector: (AV:N/AC:H/Au:N/C:P/I:N/A:N)
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving NIST webspace. We have provided these links to other web sites because
they may have information that would be of interest to you. No inferences should be drawn on account of other sites
being referenced, or not, from this page. There may be other web sites that are more appropriate for your purpose.
NIST does not necessarily endorse the views expressed, or concur with the facts presented on these sites. Further,
NIST does not endorse any commercial products that may be mentioned on these sites. Please address comments about
this page to nvd@nist.gov.
Weakness Enumeration
CWE-ID |
CWE Name |
Source |
CWE-295 |
Improper Certificate Validation |
NIST
|
Change History
1 change record found
- show changes
Initial Analysis -
1/13/2017 8:09:19 AM
Action |
Type |
Old Value |
New Value |
Added |
CPE Configuration |
|
OR
*cpe:2.3:a:python:urllib3:1.17:*:*:*:*:*:*:*
*cpe:2.3:a:python:urllib3:1.18:*:*:*:*:*:*:* |
Added |
CVSS V2 |
|
(AV:N/AC:H/Au:N/C:P/I:N/A:N) |
Added |
CVSS V3 |
|
AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N |
Added |
CWE |
|
CWE-295 |
Changed |
Reference Type |
http://www.openwall.com/lists/oss-security/2016/10/27/6 No Types Assigned |
http://www.openwall.com/lists/oss-security/2016/10/27/6 Mitigation, Mailing List |
Changed |
Reference Type |
http://www.securityfocus.com/bid/93941 No Types Assigned |
http://www.securityfocus.com/bid/93941 Third Party Advisory, VDB Entry |
Quick Info
CVE Dictionary Entry:
CVE-2016-9015
NVD Published Date:
01/11/2017
NVD Last Modified:
01/13/2017
|