PT-2020-16710 · Synopsys · Hub-Rest-Api-Python

Published

2020-11-06

·

Updated

2021-04-20

·

CVE-2020-27589

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Synopsys hub-rest-api-python (aka blackduck on PyPI) versions 0.0.25 through 0.0.52
Description The issue is related to the failure to validate SSL certificates in certain cases. This could potentially lead to security risks, as it may allow for man-in-the-middle attacks or other types of exploitation.
Recommendations For versions 0.0.25 through 0.0.52, consider updating to a version that properly validates SSL certificates to mitigate the risk. As a temporary workaround, restrict the use of the affected API to minimize the risk of exploitation.

Exploit

Fix

Improper Certificate Validation

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-27589
GHSA-F248-V4QH-X2R6
PYSEC-2020-26

Affected Products

Hub-Rest-Api-Python