QID 997505
Date Published: 2024-02-26
QID 997505: Python (Pip) Security Update for kerberos (GHSA-mffc-9gx5-99g3)
The checkPassword function in python-kerberos does not authenticate the KDC it attempts to communicate with, which allows remote attackers to cause a denial of service (bad response), or have other unspecified impact by performing a man-in-the-middle attack.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-mffc-9gx5-99g3 for updates and patch information.
Vendor References
- GHSA-mffc-9gx5-99g3 -
github.com/advisories/GHSA-mffc-9gx5-99g3
CVEs related to QID 997505
Software Advisories
| Advisory ID | Software | Component | Link |
|---|