The urllib3 library 1.26.x before 1.26.4 for Python omits SSL certificate validation in some cases involving HTTPS to HTTPS proxies. The initial connection to the HTTPS proxy (if an SSLContext isn't given via proxy_config) doesn't verify the hostname of the certificate. This means certificates for different servers that still validate properly with the default urllib3 SSLContext will be silently accepted.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2021-03-15T00:00:00

Updated: 2024-06-21T19:08:26.504484

Reserved: 2021-03-13T00:00:00


Link: CVE-2021-28363

JSON object: View

cve-icon NVD Information

Status : Modified

Published: 2021-03-15T18:15:19.017

Modified: 2024-06-21T19:15:17.763


Link: CVE-2021-28363

JSON object: View

cve-icon Redhat Information

No data.

CWE