原始 OSV JSON{
"id": "GHSA-5phf-pp7p-vc2r",
"aliases": [
"CVE-2021-28363"
],
"details": "### Impact\n\nUsers who are using an HTTPS proxy to issue HTTPS requests and haven't configured their own SSLContext via `proxy_config`.\nOnly the default SSLContext is impacted.\n\n### Patches\n\n[urllib3 >=1.26.4 has the issue resolved](https://github.com/urllib3/urllib3/releases/tag/1.26.4). urllib3<1.26 is not impacted due to not supporting HTTPS requests via HTTPS proxies.\n\n### Workarounds\n\nUpgrading is recommended as this is a minor release and not likely to break current usage.\n\nConfiguring an `SSLContext` with `check_hostname=True` and passing via `proxy_config` instead of relying on the default `SSLContext`\n\n### For more information\nIf you have any questions or comments about this advisory:\n* Email us at [[email protected] ](mailto:[email protected] )",
"summary": "Using default SSLContext for HTTPS requests in an HTTPS proxy doesn't verify certificate hostname for proxy connection",
"affected": [
{
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "1.26.0"
},
{
"fixed": "1.26.4"
}
]
}
],
"package": {
"name": "urllib3",
"ecosystem": "PyPI"
}
}
],
"modified": "2024-11-18T22:42:40Z",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N"
},
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N"
}
],
"published": "2021-03-19T19:42:11Z",
"references": [
{
"url": "https://github.com/urllib3/urllib3/security/advisories/GHSA-5phf-pp7p-vc2r",
"type": "WEB"
},
{
"url": "https://nvd.nist.gov/vuln/detail/CVE-2021-28363",
"type": "ADVISORY"
},
{
"url": "https://github.com/urllib3/urllib3/commit/8d65ea1ecf6e2cdc27d42124e587c1b83a3118b0",
"type": "WEB"
},
{
"url": "https://github.com/pypa/advisory-database/tree/main/vulns/urllib3/PYSEC-2021-59.yaml",
"type": "WEB"
},
{
"url": "https://github.com/pypa/advisory-db/tree/main/vulns/urllib3/PYSEC-2021-59.yaml",
"type": "WEB"
},
{
"url": "https://github.com/urllib3/urllib3",
"type": "PACKAGE"
},
{
"url": "https://github.com/urllib3/urllib3/blob/main/CHANGES.rst#1264-2021-03-15",
"type": "WEB"
},
{
"url": "https://github.com/urllib3/urllib3/commits/main",
"type": "WEB"
},
{
"url": "https://github.com/urllib3/urllib3/releases/tag/1.26.4",
"type": "WEB"
},
{
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4S65ZQVZ2ODGB52IC7VJDBUK4M5INCXL",
"type": "WEB"
},
{
"url": "https://lists.fedoraproject.org/archives/list/[email protected] /message/4S65ZQVZ2ODGB52IC7VJDBUK4M5INCXL",
"type": "WEB"
},
{
"url": "https://pypi.org/project/urllib3/1.26.4",
"type": "WEB"
},
{
"url": "https://security.gentoo.org/glsa/202107-36",
"type": "WEB"
},
{
"url": "https://security.gentoo.org/glsa/202305-02",
"type": "WEB"
},
{
"url": "https://security.netapp.com/advisory/ntap-20240621-0007",
"type": "WEB"
},
{
"url": "https://www.oracle.com/security-alerts/cpuoct2021.html",
"type": "WEB"
}
],
"schema_version": "1.4.0",
"database_specific": {
"cwe_ids": [
"CWE-295"
],
"severity": "MODERATE",
"github_reviewed": true,
"nvd_published_at": "2021-03-15T18:15:00Z",
"github_reviewed_at": "2021-03-19T19:41:48Z"
}
}