Man-in-the-Middle (MitM) Affecting qpid-python package, versions [0.20,1.35.0)


Severity

Recommended
0.0
medium
0
10

CVSS assessment made by Snyk's Security Team

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk ID SNYK-PYTHON-QPIDPYTHON-40465
  • published 13 May 2016
  • disclosed 13 May 2016
  • credit Lorenz Quack

Introduced: 13 May 2016

CVE NOT AVAILABLE CWE-300 Open this link in a new tab

Overview

qpid_python is a Python client implementation and AMQP conformance tests for Apache Qpid.

Affected versions of this package are vulnerable to Man-in-the-Middle attacks due to hostname verification not turned on by default. When SSL or TLS connections are being established using default configuration, it would not verify the hostname of the connecting server and an attacker could easily establish a connection.

CVSS Scores

version 3.1
Expand this section

Snyk

Recommended
6.5 medium
  • Attack Vector (AV)
    Network
  • Attack Complexity (AC)
    Low
  • Privileges Required (PR)
    None
  • User Interaction (UI)
    None
  • Scope (S)
    Unchanged
  • Confidentiality (C)
    Low
  • Integrity (I)
    Low
  • Availability (A)
    None