Man-in-the-Middle (MitM) Affecting qpid-python package, versions [0.20,1.35.0)


Severity

Recommended
0.0
medium
0
10

CVSS assessment made by Snyk's Security Team. Learn more

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-PYTHON-QPIDPYTHON-40465
  • published13 May 2016
  • disclosed13 May 2016
  • creditLorenz Quack

Introduced: 13 May 2016

CVE NOT AVAILABLE CWE-300  (opens in a new tab)

Overview

qpid_python is a Python client implementation and AMQP conformance tests for Apache Qpid.

Affected versions of this package are vulnerable to Man-in-the-Middle attacks due to hostname verification not turned on by default. When SSL or TLS connections are being established using default configuration, it would not verify the hostname of the connecting server and an attacker could easily establish a connection.

CVSS Scores

version 3.1