Safety vulnerability ID: 39070
The information on this page was manually curated by our Cybersecurity Intelligence Team.
Synopsys hub-rest-api-python (aka blackduck on PyPI) version 0.0.25 - 0.0.52 does not validate SSL certificates in certain cases. See CVE-2020-27589.
Latest version: 1.1.3
Package for using the Synopsys Black Duck Hub REST API.
Synopsys hub-rest-api-python (aka blackduck on PyPI) version 0.0.25 - 0.0.52 does not validate SSL certificates in certain cases. See CVE-2020-27589.
MISC:https://github.com/blackducksoftware/hub-rest-api-python: https://github.com/blackducksoftware/hub-rest-api-python
MISC:https://github.com/blackducksoftware/hub-rest-api-python/pull/113/commits/273b27d0de1004389dd8cf43c40b1197c787e7cd: https://github.com/blackducksoftware/hub-rest-api-python/pull/113/commits/273b27d0de1004389dd8cf43c40b1197c787e7cd
MISC:https://pypi.org/project/blackduck/: https://pypi.org/project/blackduck/
MISC:https://www.optiv.com/explore-optiv-insights/source-zero/certificate-validation-disabled-black-duck-api-wrapper: https://www.optiv.com/explore-optiv-insights/source-zero/certificate-validation-disabled-black-duck-api-wrapper
Scan your Python project for dependency vulnerabilities in two minutes
Scan your application