smart-open is vulnerable to Man-in-the-middle attack
45
Medium Risk
The connection to the FTPS server was insufficiently secured because the FTP library, by default, does not utilize SSL certificates.
You are affected by this flaw if you use the FTP secure connection functionality and version 6.3.0 or 6.4.0 of this package.
smart-open is vulnerable to Man-in-the-middle attack in versions 6.3.0 - 6.4.0.
To fix, upgrade to smart-open 7.0.0 or above.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant