SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2021-28363

The urllib3 library 1.26.x before 1.26.4 for Python omits SSL certificate validation in some cases involving HTTPS to HTTPS proxies.

MEDIUM 6.5EPSS 2.11%

Does this matter?

Lower severity and a low EPSS score (2.11%). Track it; it rarely justifies an emergency change on its own.

Description

The urllib3 library 1.26.x before 1.26.4 for Python omits SSL certificate validation in some cases involving HTTPS to HTTPS proxies. The initial connection to the HTTPS proxy (if an SSLContext isn't given via proxy_config) doesn't verify the hostname of the certificate. This means certificates for different servers that still validate properly with the default urllib3 SSLContext will be silently accepted.

CVSS 3.1
6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
EPSS
2.11% probability · 81th percentile
CISA KEV
Not listed
Weakness
CWE-295
Affected
python/urllib3 · fedoraproject/fedora · oracle/peoplesoft enterprise peopletools
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.