Back to search
CVE-2019-11324
Published: Apr 18, 2019
Modified: Aug 4, 2024
PUBLISHED
Description
The urllib3 library before 1.24.2 for Python mishandles certain cases where the desired set of CA certificates is different from the OS store of CA certificates, which results in SSL connections succeeding in situations where a verification failure is the correct outcome. This is related to use of the ssl_context, ca_certs, or ca_certs_dir argument.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
USN-3990-1
vendor-advisory
openSUSE-SU-2019:2131
vendor-advisory
openSUSE-SU-2019:2133
vendor-advisory
RHSA-2019:3590
vendor-advisory
RHSA-2019:3335
vendor-advisory
FEDORA-2020-6148c44137
vendor-advisory
FEDORA-2020-d0d9ad17d8
vendor-advisory
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now