Intel

AIKIDO-2024-10003

smart-open is vulnerable to Man-in-the-middle attack

Man-in-the-middle attack Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Feb 26, 2024

45

Medium Risk

This Affects:

pythonsmart-open
6.3.0 - 6.4.0
Fixed in 7.0.0
Are you affected? Scan for Free

TL;DR

The connection to the FTPS server was insufficiently secured because the FTP library, by default, does not utilize SSL certificates.

Who does this affect?

You are affected by this flaw if you use the FTP secure connection functionality and version 6.3.0 or 6.4.0 of this package.

Background info

smart-open is vulnerable to Man-in-the-middle attack in versions 6.3.0 - 6.4.0.

How to fix this

To fix, upgrade to smart-open 7.0.0 or above.