{"id":"CVE-2017-1000007","aliases":["PYSEC-2017-85"],"url":"https://o3.security/vulnerability/CVE-2017-1000007","summary":"txAWS AWSServiceEndpoint defaults to not verifying server certificates","details":"txAWS fails to perform complete certificate verification resulting in vulnerability to MitM attacks and information disclosure.","published":"2022-05-17T02:20:12Z","modified":"2024-11-18T23:02:31.402394Z","cvss":{"score":5.9,"severity":"MEDIUM","vector":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"txaws","fixedVersion":"0.4.0"}],"fix":{"url":"https://github.com/twisted/txaws/pull/26","label":"twisted/txaws#26"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2017-1000007"},{"type":"WEB","url":"https://github.com/twisted/txaws/issues/24"},{"type":"WEB","url":"https://github.com/twisted/txaws/pull/26"},{"type":"WEB","url":"https://github.com/twisted/txaws/commit/46b66c3dc315de7b5896d60531311ec9658bc466"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/txaws/PYSEC-2017-85.yaml"},{"type":"PACKAGE","url":"https://github.com/twisted/txaws"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2024-11-18T23:02:31.402394Z"}}