cbcvebase.
CVE-2024-31884
published 2026-01-20

CVE-2024-31884: pybind: Improper use of Pybind A flaw was found in Ceph. An attacker can allow Ceph to accept any certificate because no certificate context is passed via…

high7.5
pybind: Improper use of Pybind A flaw was found in Ceph. An attacker can allow Ceph to accept any certificate because no certificate context is passed via Pybind to the constructors imaplib.IMAP4_SSL or smtplib.SMTP_SSL. As a result, pybind pybind does not check the server's X.509 certificate, instead accepting any certificate. This enables an attacker to commit a Man In the Middle (MITM) attack, compromising mail server credentials or mail contents Mitigation: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Affected

1 ranges
VendorProductVersion rangeFixed in
debianceph< ceph 14.2.21-1+deb11u3 (bullseye)ceph 14.2.21-1+deb11u3 (bullseye)

CVSS provenance

osv7.5HIGH
vendor_ubuntu7.5HIGH
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.