—
PYSEC-2017-49
Details
The checkPassword function in python-kerberos does not authenticate the KDC it attempts to communicate with, which allows remote attackers to cause a denial of service (bad response), or have other unspecified impact by performing a man-in-the-middle attack.
Are you affected?
Enter the version of the package you're using.
Affected packages
PyPI/kerberos
Introduced in:
0.0No fixed version published yet for kerberos (pip). Pin to a known-safe version or switch to an alternative.