CVE-2021-28363
published 2021-03-15CVE-2021-28363: The urllib3 library 1.26.x before 1.26.4 for Python omits SSL certificate validation in some cases involving HTTPS to HTTPS proxies. The initial connection to…
PriorityP433medium6.5CVSS 3.1
AVNACLPRNUINSUCLILAN
EPSS
2.11%
79.8th percentile
The urllib3 library 1.26.x before 1.26.4 for Python omits SSL certificate validation in some cases involving HTTPS to HTTPS proxies. The initial connection to the HTTPS proxy (if an SSLContext isn't given via proxy_config) doesn't verify the hostname of the certificate. This means certificates for different servers that still validate properly with the default urllib3 SSLContext will be silently accepted.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | python-urllib3 | < python-urllib3 1.26.4-1 (bookworm) | python-urllib3 1.26.4-1 (bookworm) |
| fedoraproject | fedora | — | — |
| oracle | peoplesoft_enterprise_peopletools | — | — |
| python | urllib3 | >= 1.26.0 < 1.26.4 | 1.26.4 |
| urllib3 | urllib3 | >= 1.26.0 < 1.26.4 | 1.26.4 |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
nvdv2.06.4MEDIUMAV:N/AC:L/Au:N/C:P/I:P/A:N
osv6.5MEDIUM
vendor_debian6.5MEDIUM
vendor_oracle6.5MEDIUM
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Using default SSLContext for HTTPS requests in an HTTPS proxy doesn't verify certificate hostname for proxy connection
osv·2021-03-19
CVE-2021-28363 [MEDIUM] Using default SSLContext for HTTPS requests in an HTTPS proxy doesn't verify certificate hostname for proxy connection
Using default SSLContext for HTTPS requests in an HTTPS proxy doesn't verify certificate hostname for proxy connection
### Impact
Users who are using an HTTPS proxy to issue HTTPS requests and haven't configured their own SSLContext via `proxy_config`.
Only the default SSLContext is impacted.
### Patches
[urllib3 >=1.26.4 has the issue resolved](https://github.com/urllib3/urllib3/releases/tag/1.26.4). urllib3<1.26 is not impacted due to not supporting HTTPS requests via HTTPS proxies.
### Workarounds
Upgrading is recommended as this is a minor release and not likely to break current usage.
Configuring an `SSLContext` with `check_hostname=True` and passing via `proxy_config` instead of relying on the default `SSLContext`
### For more information
If you have any questions or comments
GHSA
Using default SSLContext for HTTPS requests in an HTTPS proxy doesn't verify certificate hostname for proxy connection
ghsa·2021-03-19
CVE-2021-28363 [MEDIUM] CWE-295 Using default SSLContext for HTTPS requests in an HTTPS proxy doesn't verify certificate hostname for proxy connection
Using default SSLContext for HTTPS requests in an HTTPS proxy doesn't verify certificate hostname for proxy connection
### Impact
Users who are using an HTTPS proxy to issue HTTPS requests and haven't configured their own SSLContext via `proxy_config`.
Only the default SSLContext is impacted.
### Patches
[urllib3 >=1.26.4 has the issue resolved](https://github.com/urllib3/urllib3/releases/tag/1.26.4). urllib3<1.26 is not impacted due to not supporting HTTPS requests via HTTPS proxies.
### Workarounds
Upgrading is recommended as this is a minor release and not likely to break current usage.
Configuring an `SSLContext` with `check_hostname=True` and passing via `proxy_config` instead of relying on the default `SSLContext`
### For more information
If you have any questions or comments
OSV
CVE-2021-28363: The urllib3 library 1
osv·2021-03-15·CVSS 6.5
CVE-2021-28363 [MEDIUM] CVE-2021-28363: The urllib3 library 1
The urllib3 library 1.26.x before 1.26.4 for Python omits SSL certificate validation in some cases involving HTTPS to HTTPS proxies. The initial connection to the HTTPS proxy (if an SSLContext isn't given via proxy_config) doesn't verify the hostname of the certificate. This means certificates for different servers that still validate properly with the default urllib3 SSLContext will be silently accepted.
Oracle
Oracle Oracle PeopleSoft Risk Matrix: Porting (urllib3) — CVE-2021-28363
vendor_oracle·2021-10-15·CVSS 6.5
CVE-2021-28363 [MEDIUM] Oracle Oracle PeopleSoft Risk Matrix: Porting (urllib3) — CVE-2021-28363
Oracle Oracle PeopleSoft Risk Matrix: Porting (urllib3) vulnerability
CVE: CVE-2021-28363
CVSS: 6.5
Protocol: HTTPS
Remote exploit: Yes
Affected versions: Network
Advisory: cpuoct2021 (OCT 2021)
Red Hat
python-urllib3: HTTPS proxy host name not validated when using default SSLContext
vendor_redhat·2021-03-15·CVSS 6.5
CVE-2021-28363 [MEDIUM] CWE-295 python-urllib3: HTTPS proxy host name not validated when using default SSLContext
python-urllib3: HTTPS proxy host name not validated when using default SSLContext
The urllib3 library 1.26.x before 1.26.4 for Python omits SSL certificate validation in some cases involving HTTPS to HTTPS proxies. The initial connection to the HTTPS proxy (if an SSLContext isn't given via proxy_config) doesn't verify the hostname of the certificate. This means certificates for different servers that still validate properly with the default urllib3 SSLContext will be silently accepted.
A flaw was found in python-urllib3. SSL certificate validation is omitted in some cases involving HTTPS to HTTPS proxies. The initial connection to the HTTPS proxy (if an SSLContext isn't given via proxy_config) doesn't verify the hostname of the certificate. This means certificates for different servers t
Debian
CVE-2021-28363: python-urllib3 - The urllib3 library 1.26.x before 1.26.4 for Python omits SSL certificate valida...
vendor_debian·2021·CVSS 6.5
CVE-2021-28363 [MEDIUM] CVE-2021-28363: python-urllib3 - The urllib3 library 1.26.x before 1.26.4 for Python omits SSL certificate valida...
The urllib3 library 1.26.x before 1.26.4 for Python omits SSL certificate validation in some cases involving HTTPS to HTTPS proxies. The initial connection to the HTTPS proxy (if an SSLContext isn't given via proxy_config) doesn't verify the hostname of the certificate. This means certificates for different servers that still validate properly with the default urllib3 SSLContext will be silently accepted.
Scope: local
bookworm: resolved (fixed in 1.26.4-1)
bullseye: resolved (fixed in 1.26.4-1)
forky: resolved (fixed in 1.26.4-1)
sid: resolved (fixed in 1.26.4-1)
trixie: resolved (fixed in 1.26.4-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/urllib3/urllib3/commit/8d65ea1ecf6e2cdc27d42124e587c1b83a3118b0https://github.com/urllib3/urllib3/commits/mainhttps://github.com/urllib3/urllib3/security/advisories/GHSA-5phf-pp7p-vc2rhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4S65ZQVZ2ODGB52IC7VJDBUK4M5INCXL/https://pypi.org/project/urllib3/1.26.4/https://security.gentoo.org/glsa/202107-36https://security.gentoo.org/glsa/202305-02https://security.netapp.com/advisory/ntap-20240621-0007/https://www.oracle.com/security-alerts/cpuoct2021.htmlhttps://github.com/urllib3/urllib3/commit/8d65ea1ecf6e2cdc27d42124e587c1b83a3118b0https://github.com/urllib3/urllib3/commits/mainhttps://github.com/urllib3/urllib3/security/advisories/GHSA-5phf-pp7p-vc2rhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4S65ZQVZ2ODGB52IC7VJDBUK4M5INCXL/https://pypi.org/project/urllib3/1.26.4/https://security.gentoo.org/glsa/202107-36https://security.gentoo.org/glsa/202305-02https://security.netapp.com/advisory/ntap-20240621-0007/https://www.oracle.com/security-alerts/cpuoct2021.html
2021-03-15
Published