pywbem@0.7.0 vulnerabilities

pywbem - A WBEM client

  • latest version

    1.7.2

  • latest non vulnerable version

  • first published

    9 years ago

  • latest version published

    8 months ago

  • licenses detected

  • Direct Vulnerabilities

    Known vulnerabilities in the pywbem package. This does not include vulnerabilities belonging to this package’s dependencies.

    How to fix?

    Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.

    Fix for free
    VulnerabilityVulnerable Version
    • M
    Man in the Middle (MitM)

    pywbem is a pywbem - A WBEM client PyWBEM 0.7 and earlier does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.

    [,0.7.0]
    • M
    Man-in-the-Middle (MitM)

    pywbem is a pywbem - A WBEM client PyWBEM 0.7 and earlier uses a separate connection to validate X.509 certificates, which allows man-in-the-middle attackers to spoof a peer via an arbitrary certificate.

    [,0.7.0]