CVE-2023-40217

    Dashboard / Vulnerabilities / CVE-2023-40217

    CVE-2023-40217

    Published: 25 Aug 2023Last Modified: 12 Aug 2026

    Summary:

    Details: An issue was discovered in Python before 3.8.18, 3.9.x before 3.9.18, 3.10.x before 3.10.13, and 3.11.x before 3.11.5. It primarily affects servers (such as HTTP servers) that use TLS client authentication. If a TLS server-side socket is created, receives data into the socket buffer, and then is closed quickly, there is a brief window where the SSLSocket instance will detect the socket as "not connected" and won't initiate a handshake, but buffered data will still be readable from the socket buffer. This data will not be authenticated if the server-side TLS peer is expecting client certificate authentication, and is indistinguishable from valid TLS stream data. Data is limited in size to the amount that will fit in the buffer. (The TLS connection cannot directly be used for data exfiltration because the vulnerable code path requires that the connection be closed on initialization of the SSLSocket.)

    Affected packages

    Package

    Name:

    Purl:

    Affected ranges

    Type: GIT

    Events:

    Affected versions

    v3.11.4
    v3.11.3
    v3.11.2
    v3.11.1
    v3.11.0rc2
    v3.11.0rc1
    v3.11.0b5
    v3.11.0b4
    v3.11.0b3
    v3.11.0b2
    v3.11.0b1
    v3.11.0a7
    v3.11.0a6
    v3.11.0a5
    v3.11.0a4
    v3.11.0a3

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    CVE-2023-40217 | CVE-DB