The urllib3 library before 1.24.2 for Python mishandles certain cases where the desired set of CA certificates is different from the OS store of CA certificates, which results in SSL connections succeeding in situations where a verification failure is the correct outcome. This is related to use of the ssl_context, ca_certs, or ca_certs_dir argument.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2019-04-18T00:00:00

Updated: 2023-10-08T13:06:16.727428

Reserved: 2019-04-18T00:00:00


Link: CVE-2019-11324

JSON object: View

cve-icon NVD Information

Status : Modified

Published: 2019-04-18T21:29:00.883

Modified: 2023-11-07T03:02:59.113


Link: CVE-2019-11324

JSON object: View

cve-icon Redhat Information

No data.

CWE