Description: "The urllib3 library 1.26.x before 1.26.4 for Python omits SSL certificate validation in some cases involving HTTPS to HTTPS proxies. The initial connection to the HTTPS proxy (if an SSLContext isn't given via proxy_config) doesn't verify the hostname of the certificate. This means certificates for different servers that still validate properly with the default urllib3 SSLContext will be silently accepted."
Tell us when ready to stable.
ping
Sorry, thought you CC-ed arches when adding package list ;-).
hppa stable
amd64 arm arm64 ppc ppc64 s390 sparc x86 (ALLARCHES) done all arches done
Please cleanup.
The bug has been referenced in the following commit(s): https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=ce9fd297c7434fbe409440a054bee6efd526ef41 commit ce9fd297c7434fbe409440a054bee6efd526ef41 Author: Michał Górny <mgorny@gentoo.org> AuthorDate: 2021-03-26 08:29:09 +0000 Commit: Michał Górny <mgorny@gentoo.org> CommitDate: 2021-03-26 09:41:30 +0000 dev-python/urllib3: Remove old Bug: https://bugs.gentoo.org/776421 Signed-off-by: Michał Górny <mgorny@gentoo.org> dev-python/urllib3/Manifest | 2 - dev-python/urllib3/urllib3-1.25.11.ebuild | 69 ---------------------------- dev-python/urllib3/urllib3-1.26.3-r1.ebuild | 71 ----------------------------- 3 files changed, 142 deletions(-)
GLSA request filed.
This issue was resolved and addressed in GLSA 202107-36 at https://security.gentoo.org/glsa/202107-36 by GLSA coordinator John Helmert III (ajak).