Man-in-the-Middle (MitM) Affecting deis package, versions [,1.4)


Severity

Recommended
0.0
low
0
10

CVSS assessment made by Snyk's Security Team. Learn more

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about Man-in-the-Middle (MitM) vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-PYTHON-DEIS-42036
  • published7 Nov 2017
  • disclosed15 Feb 2015
  • creditArne-Christian Blystad

Introduced: 15 Feb 2015

CVE NOT AVAILABLE CWE-310  (opens in a new tab)

Overview

deis is a command-line Client for Deis, the open PaaS.

Affected versions of this package are vulnerable to Man-in-the-Middle (MitM). The SSL protocol 3.0, as used in OpenSSL through 1.0.1i and other products, uses nondeterministic CBC padding, which makes it easier for man-in-the-middle attackers to obtain cleartext data via a padding-oracle attack, aka the "POODLE" issue.

CVSS Base Scores

version 3.1