PT-2020-16710 · Synopsys · Hub-Rest-Api-Python
Published
2020-11-06
·
Updated
2021-04-20
·
CVE-2020-27589
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Synopsys hub-rest-api-python (aka blackduck on PyPI) versions 0.0.25 through 0.0.52
Description
The issue is related to the failure to validate SSL certificates in certain cases. This could potentially lead to security risks, as it may allow for man-in-the-middle attacks or other types of exploitation.
Recommendations
For versions 0.0.25 through 0.0.52, consider updating to a version that properly validates SSL certificates to mitigate the risk. As a temporary workaround, restrict the use of the affected API to minimize the risk of exploitation.
Exploit
Fix
Improper Certificate Validation
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Hub-Rest-Api-Python