Skip to content

Latest commit

 

History

History
7 lines (7 loc) · 400 Bytes

2023-08-22-17-39-12.gh-issue-108310.fVM3sg.rst

File metadata and controls

7 lines (7 loc) · 400 Bytes

Fixed an issue where instances of ssl.SSLSocket were vulnerable to a bypass of the TLS handshake and included protections (like certificate verification) and treating sent unencrypted data as if it were post-handshake TLS encrypted data. Security issue reported as CVE-2023-40217 by Aapo Oksman. Patch by Gregory P. Smith.