Miggo Logo

CVE-2021-28363: Using default SSLContext for HTTPS requests in an HTTPS proxy doesn't verify certificate hostname for proxy connection

6.5

CVSS Score
3.1

Basic Information

EPSS Score
0.35727%
Published
3/19/2021
Updated
11/18/2024
KEV Status
No
Technology
TechnologyPython

Technical Details

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Package NameEcosystemVulnerable VersionsFirst Patched Version
urllib3pip>= 1.26.0, < 1.26.41.26.4

Vulnerability Intelligence
Miggo AIMiggo AI

Miggo AIRoot Cause Analysis:
In progress

WAF Protection Rules

WAF Rule

### Imp**t Us*rs w*o *r* usin* *n *TTPS proxy to issu* *TTPS r*qu*sts *n* **v*n't *on*i*ur** t**ir own SSL*ont*xt vi* `proxy_*on*i*`. Only t** ****ult SSL*ont*xt is imp**t**. ### P*t***s [urlli** >=*.**.* **s t** issu* r*solv**](*ttps://*it*u*.*om

Reasoning

No *n*lysis *v*il**l*