CVE-2019-11324
Summary
| CVE | CVE-2019-11324 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-04-18 21:29:00 UTC |
| Updated | 2023-11-07 03:02:00 UTC |
| Description | The urllib3 library before 1.24.2 for Python mishandles certain cases where the desired set of CA certificates is different from the OS store of CA certificates, which results in SSL connections succeeding in situations where a verification failure is the correct outcome. This is related to use of the ssl_context, ca_certs, or ca_certs_dir argument. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| [SECURITY] [DLA 2686-1] python-urllib3 security update |
MLIST |
lists.debian.org |
|
| [SECURITY] [DLA 3610-1] python-urllib3 security update |
MLIST |
lists.debian.org |
|
| oss-security - Re: urllib3: adds system certificates to ssl_context |
MLIST |
www.openwall.com |
Mailing List, Third Party Advisory |
| USN-3990-1: urllib3 vulnerabilities | Ubuntu security notices |
UBUNTU |
usn.ubuntu.com |
Third Party Advisory |
| Red Hat Customer Portal |
REDHAT |
access.redhat.com |
|
| Comparing a6ec68a...1efadf4 · urllib3/urllib3 · GitHub |
MISC |
github.com |
Patch, Third Party Advisory |
| [SECURITY] Fedora 30 Update: python-pip-19.0.3-6.fc30 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| [security-announce] openSUSE-SU-2019:2133-1: moderate: Security update f |
SUSE |
lists.opensuse.org |
|
| [SECURITY] Fedora 31 Update: python-pip-19.1.1-7.fc31 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| Red Hat Customer Portal |
REDHAT |
access.redhat.com |
|
| [SECURITY] Fedora 31 Update: python-pip-19.1.1-7.fc31 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| [SECURITY] Fedora 30 Update: python-pip-19.0.3-6.fc30 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| [security-announce] openSUSE-SU-2019:2131-1: moderate: Security update f |
SUSE |
lists.opensuse.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 159655 Oracle Enterprise Linux Security Update for python27:2.7 (ELSA-2020-1605)
- 159668 Oracle Enterprise Linux Security Update for python27:2.7 security and bug fix update (ELSA-2019-3335)
- 178673 Debian Security Update for python-urllib3 (DLA 2686-1)
- 377534 Alibaba Cloud Linux Security Update for python-pip (ALINUX2-SA-2020:0030)
- 377557 Alibaba Cloud Linux Security Update for python27:2.7 (ALINUX3-SA-2022:0112)
- 6000046 Debian Security Update for python-urllib3 (DLA 3610-1)
- 670234 EulerOS Security Update for python-urllib3 (EulerOS-SA-2021-1842)
- 940120 AlmaLinux Security Update for python27:2.7 (ALSA-2020:1605)
- 940202 AlmaLinux Security Update for python27:2.7 (ALSA-2019:3335)
- 982225 Python (pip) Security Update for urllib3 (GHSA-mh33-7rrq-662w)