pywbem@0.7.0 vulnerabilities

pywbem - A WBEM client

  • latest version

    1.8.0

  • latest non vulnerable version

  • first published

    10 years ago

  • latest version published

    21 days ago

  • licenses detected

  • Direct Vulnerabilities

    Known vulnerabilities in the pywbem package. This does not include vulnerabilities belonging to this package’s dependencies.

    Fix vulnerabilities automatically

    Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

    Fix for free
    VulnerabilityVulnerable Version
    • M
    Man in the Middle (MitM)

    pywbem is a pywbem - A WBEM client PyWBEM 0.7 and earlier does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.

    [,0.7.0]
    • M
    Man-in-the-Middle (MitM)

    pywbem is a pywbem - A WBEM client PyWBEM 0.7 and earlier uses a separate connection to validate X.509 certificates, which allows man-in-the-middle attackers to spoof a peer via an arbitrary certificate.

    [,0.7.0]