{"id":"GHSA-f248-v4qh-x2r6","summary":"Improper Certificate Validation in blackduck","details":"Synopsys hub-rest-api-python (aka blackduck on PyPI) version 0.0.25 - 0.0.52 does not validate SSL certificates in certain cases.","aliases":["CVE-2020-27589","PYSEC-2020-26"],"modified":"2024-09-13T18:02:52.911555Z","published":"2021-04-20T16:29:41Z","database_specific":{"github_reviewed_at":"2021-04-19T23:38:37Z","github_reviewed":true,"nvd_published_at":"2020-11-06T14:15:00Z","severity":"HIGH","cwe_ids":["CWE-295"]},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2020-27589"},{"type":"WEB","url":"https://github.com/blackducksoftware/hub-rest-api-python/pull/113"},{"type":"WEB","url":"https://github.com/blackducksoftware/hub-rest-api-python/commit/0a25777117515b8b4ff287a98f57837a8c6bdbdb"},{"type":"WEB","url":"https://community.synopsys.com/s/question/0D52H00005JCZAXSA5/announcement-black-duck-defect-identified"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-f248-v4qh-x2r6"},{"type":"PACKAGE","url":"https://github.com/blackducksoftware/hub-rest-api-python"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/blackduck/PYSEC-2020-26.yaml"},{"type":"WEB","url":"https://pypi.org/project/blackduck"},{"type":"WEB","url":"https://www.optiv.com/explore-optiv-insights/source-zero/certificate-validation-disabled-black-duck-api-wrapper"}],"affected":[{"package":{"name":"blackduck","ecosystem":"PyPI","purl":"pkg:pypi/blackduck"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0.0.25"},{"fixed":"0.0.53"}]}],"versions":["0.0.25","0.0.26","0.0.27","0.0.28","0.0.29","0.0.30","0.0.31","0.0.32","0.0.33","0.0.34","0.0.35","0.0.36","0.0.37","0.0.38","0.0.39","0.0.40","0.0.41","0.0.42","0.0.43","0.0.44","0.0.45","0.0.46","0.0.47","0.0.48","0.0.49","0.0.50","0.0.51","0.0.52"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/04/GHSA-f248-v4qh-x2r6/GHSA-f248-v4qh-x2r6.json"}}],"schema_version":"1.7.3","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N"}]}