python-scciclient vulnerable to Man-in-the-middle (MITM) attacks
Critical severity
GitHub Reviewed
Published
Sep 2, 2022
to the GitHub Advisory Database
•
Updated Nov 26, 2024
Description
Published by the National Vulnerability Database
Sep 1, 2022
Published to the GitHub Advisory Database
Sep 2, 2022
Reviewed
Sep 16, 2022
Last updated
Nov 26, 2024
A flaw was found in the python-scciclient when making an HTTPS connection to a server where the server's certificate would not be verified. This issue opens up the connection to possible Man-in-the-middle (MITM) attacks.
References