{"id":"PYSEC-2019-203","details":"Splunk-SDK-Python before 1.6.6 does not properly verify untrusted TLS server certificates, which could result in man-in-the-middle attacks.","aliases":["CVE-2019-5729","GHSA-f58w-649r-qjr9"],"modified":"2023-11-08T04:01:37.141304Z","published":"2019-03-21T16:01:00Z","references":[{"type":"WEB","url":"https://www.splunk.com/view/SP-CAAAQAD"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-f58w-649r-qjr9"}],"affected":[{"package":{"name":"splunk-sdk","ecosystem":"PyPI","purl":"pkg:pypi/splunk-sdk"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.6.6"}]}],"versions":["0.1.0","0.1.0a","0.8.0","1.0.0","1.1.0","1.2.0","1.2.1","1.2.2","1.2.3","1.3.0","1.3.1","1.4.0","1.5.0","1.6.0","1.6.1","1.6.2","1.6.3","1.6.4","1.6.5"],"database_specific":{"source":"https://github.com/pypa/advisory-database/blob/main/vulns/splunk-sdk/PYSEC-2019-203.yaml"}}],"schema_version":"1.7.3"}