Intel

AIKIDO-2024-10417

urllib3-future is vulnerable to Inadequate Encryption Strength

Inadequate Encryption Strength Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Nov 5, 2024

50

Medium Risk

This Affects:

pythonurllib3-future
2.0.931 - 2.11.907
Fixed in 2.11.908
Are you affected? Scan for Free

TL;DR

Affected versions of this package allow the use of insecure TLS 1.0 and TLS 1.1 protocols, exposing communications to man-in-the-middle attacks. This vulnerability compromises the confidentiality and integrity of data by enabling attackers to intercept and manipulate the data being transmitted.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

urllib3-future is vulnerable to Inadequate Encryption Strength in versions 2.0.931 - 2.11.907.

How to fix this

Upgrade the urllib3-future library to the patch version.