CVE-2022-2996
Summary
| CVE | CVE-2022-2996 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-09-01 18:15:00 UTC |
| Updated | 2022-12-12 21:09:00 UTC |
| Description | A flaw was found in the python-scciclient when making an HTTPS connection to a server where the server's certificate would not be verified. This issue opens up the connection to possible Man-in-the-middle (MITM) attacks. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| Add parameter to specify certification file · 274dca0344 - python-scciclient - OpenDev: Free Software Needs Free Tools |
MISC |
opendev.org |
|
| [SECURITY] [DLA 3180-1] python-scciclient security update |
MLIST |
lists.debian.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 181195 Debian Security Update for python-scciclient (DLA 3180-1)
- 182608 Debian Security Update for python-scciclient (CVE-2022-2996)
- 240973 Red Hat Update for OpenStack Platform 16.1.9 (RHSA-2022:8868)
- 240983 Red Hat Update for OpenStack Platform 16.2.4 (RHSA-2022:8854)
- 241138 Red Hat Update for OpenStack Platform 17.0 (RHSA-2023:0276)