python-scciclient vulnerable to Man-in-the-middle (MITM) attacks
High severity
GitHub Reviewed
Published
Sep 2, 2022
to the GitHub Advisory Database
•
Updated Jan 28, 2023
Description
Published by the National Vulnerability Database
Sep 1, 2022
Published to the GitHub Advisory Database
Sep 2, 2022
Reviewed
Sep 16, 2022
Last updated
Jan 28, 2023
A flaw was found in the python-scciclient when making an HTTPS connection to a server where the server's certificate would not be verified. This issue opens up the connection to possible Man-in-the-middle (MITM) attacks.
References