CVE Feed

    Dashboard / CVE / CVE-2021-28363

    CVE-2021-28363

    The urllib3 library 1.26.x before 1.26.4 for Python omits SSL certificate validation in some cases involving HTTPS to HTTPS proxies. The initial connection to the HTTPS proxy (if an SSLContext isn't given via proxy_config) doesn't verify the hostname of the certificate. This means certificates for different servers that still validate properly with the default urllib3 SSLContext will be silently accepted.

    Published:Mar 15, 2021
    Last Modified:Nov 21, 2024
    EPS:Mar 15, 2021
    EPSS Score:0.00107
    CVSS Score:6.5

    Affected Products

    Vendor
    Fedoraproject
    Product
    Fedora
    Vendor
    Oracle
    Product
    Peoplesoft Enterprise Peopletools
    Vendor
    Python
    Product
    Urllib3
    Vendor
    Redhat
    Product
    Openshift

    Exploits

    No exploit reference

    Common Weakness Enumeration

    Related CVEs

    References

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High