VDB
Sign up
HIGH7.4

PYSEC-2022-43152

Quick fix

PYSEC-2022-43152 — python-scciclient: upgrade to the fixed version with the command below.

pip install --upgrade 'python-scciclient>=0.12.0'

Details

A flaw was found in the python-scciclient when making an HTTPS connection to a server where the server's certificate would not be verified. This issue opens up the connection to possible Man-in-the-middle (MITM) attacks.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/python-scciclient
Introduced in: 0Fixed in: 0.12.0
Fixpip install --upgrade 'python-scciclient>=0.12.0'

References