Hello I have an message into the return of my arch-audit: "python-urllib3 is affected by certificate verification bypass. High risk!"
What is the signification ? It's the code of 'python-urllib3' have an security breach ? Or else ? Because if I understand really good... it's an part of the code or this lib have incapacity of good check the certifications of asymmetric encrypted communication ? So I think about reverse-shell and a lot of attacks possibles, it's dangerous, I think not tell bullshit if I tell: anybody can exploit this for usurpation of the certificate and take the control of an SSL/TLS transmission ? All right ? ...
I don't know, Sorry for my bad and poor english, and if my question is stupid at other look side.
I try to learn, I eat Arch Wiki.
- Rick.