CVE-2021-28363
high
CVSS v3
—
CVSS v2
—
VIR risk
8.0
Description
The urllib3 library 1.26.x before 1.26.4 for Python omits SSL certificate validation in some cases involving HTTPS to HTTPS proxies. The initial connection to the HTTPS proxy (if an SSLContext isn't given via proxy_config) doesn't verify the hostname of the certificate. This means certificates for different servers that still validate properly with the default urllib3 SSLContext will be silently accepted.
Predictions
Exploit likelihood
30%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2021-28363
Vendor advisory: suse — https://www.suse.com/security/cve/CVE-2021-28363.html
OS impact
| OS | Version | Status | Fixed in |
|---|---|---|---|
| arch | fixed | 1.26.4-1 | |
| sles | affected | | |
| debian | bookworm | fixed | 1.26.4-1 |
| debian | bullseye | fixed | 1.26.4-1 |
| debian | forky | fixed | 1.26.4-1 |
| debian | sid | fixed | 1.26.4-1 |
| debian | trixie | fixed | 1.26.4-1 |
References
- https://github.com/urllib3/urllib3/security/advisories/GHSA-5phf-pp7p-vc2r
- https://nvd.nist.gov/vuln/detail/CVE-2021-28363
- https://github.com/urllib3/urllib3/commit/8d65ea1ecf6e2cdc27d42124e587c1b83a3118b0
- https://github.com/pypa/advisory-database/tree/main/vulns/urllib3/PYSEC-2021-59.yaml
- https://github.com/pypa/advisory-db/tree/main/vulns/urllib3/PYSEC-2021-59.yaml
- https://github.com/urllib3/urllib3
- https://github.com/urllib3/urllib3/blob/main/CHANGES.rst#1264-2021-03-15
- https://github.com/urllib3/urllib3/commits/main
- https://github.com/urllib3/urllib3/releases/tag/1.26.4
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4S65ZQVZ2ODGB52IC7VJDBUK4M5INCXL
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/4S65ZQVZ2ODGB52IC7VJDBUK4M5INCXL
- https://pypi.org/project/urllib3/1.26.4
- https://security.gentoo.org/glsa/202107-36
- https://security.gentoo.org/glsa/202305-02
- https://security.netapp.com/advisory/ntap-20240621-0007
- https://www.oracle.com/security-alerts/cpuoct2021.html
- https://pypi.org/project/urllib3/1.26.4/
- https://www.suse.com/security/cve/CVE-2021-28363.html
- https://security-tracker.debian.org/tracker/CVE-2021-28363
Verify integrity in audit chain (admin only). AS-IS.