PT-2019-2331 · Python+8 · Urllib3+8

Christian Heimes

·

Published

2019-04-17

·

Updated

2026-06-03

·

CVE-2019-11324

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions urllib3 versions prior to 1.24.2
Description The issue is related to the mishandling of certain cases where the desired set of CA certificates is different from the OS store of CA certificates, resulting in SSL connections succeeding in situations where a verification failure is the correct outcome. This is related to the use of the ssl context, ca certs, or ca certs dir argument. The vulnerability may allow a remote attacker to establish an SSL connection despite certificate verification errors.
Recommendations For versions prior to 1.24.2, update to version 1.24.2 or later to resolve the issue. As a temporary workaround, consider restricting the use of the ssl context, ca certs, or ca certs dir argument until a patch is available.

Fix

Improper Certificate Validation

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2019:3335
ALSA-2020:1605
ALT-PU-2019-1709
BDU:2019-02105
CESA-2019_3335
CESA-2019_3590
CESA-2020_0850
CESA-2020_1605
CESA-2020_1916
CVE-2019-11324
DLA-2686-1
DLA-3610-1
GHSA-MH33-7RRQ-662W
MGASA-2019-0258
MGASA-2020-0063
OPENSUSE-SU-2019:2131-1
OPENSUSE-SU-2019:2133-1
OPENSUSE-SU-2019_2131-1
OPENSUSE-SU-2019_2133-1
OPENSUSE-SU-2024:11234-1
OPENSUSE-SU-2024:11255-1
OPENSUSE-SU-2024:11277-1
OPENSUSE-SU-2024:12944-1
OPENSUSE-SU-2024:14055-1
OPENSUSE-SU-2024:14144-1
PYSEC-2019-133
RHSA-2019:3335
RHSA-2019:3590
RHSA-2019_3335
RHSA-2019_3590
RHSA-2020:0850
RHSA-2020:1605
RHSA-2020:1916
RHSA-2020:2068
RHSA-2020_0850
RHSA-2020_1605
RHSA-2020_1916
RHSA-2020_2068
RLSA-2019:3335
RLSA-2020:1605
SUSE-FU-2022:0444-1
SUSE-FU-2022:0445-1
SUSE-SU-2019:2267-1
SUSE-SU-2019:2300-1
SUSE-SU-2019:2331-1
SUSE-SU-2019:2332-1
SUSE-SU-2019:2370-1
SUSE-SU-2019:2391-1
USN-3990-1

Affected Products

Alt Linux
Almalinux
Astra Linux
Centos
Red Hat
Rocky Linux
Suse
Ubuntu
Urllib3