Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-7f2c-vp52-gmfw

Опубликовано: 17 мая 2022
Источник: github
Github: Прошло ревью
CVSS4: 8.2
CVSS3: 5.9

Описание

OpenStack keystonemiddleware does not verify certificate

OpenStack keystonemiddleware (formerly python-keystoneclient) 0.x before 0.11.0 and 1.x before 1.2.0 disables certification verification when the "insecure" option is set in a paste configuration (paste.ini) file regardless of the value, which allows remote attackers to conduct man-in-the-middle attacks via a crafted certificate.

Пакеты

Наименование

keystonemiddleware

pip
Затронутые версииВерсия исправления

< 0.11.0

0.11.0

Наименование

keystonemiddleware

pip
Затронутые версииВерсия исправления

>= 1.0, < 1.2.0

1.2.0

Наименование

python-keystoneclient

pip
Затронутые версииВерсия исправления

< 0.11.0

0.11.0

Наименование

python-keystoneclient

pip
Затронутые версииВерсия исправления

>= 1.0, < 1.2.0

1.2.0

EPSS

Процентиль: 58%
0.00365
Низкий

8.2 High

CVSS4

5.9 Medium

CVSS3

Дефекты

CWE-295

Связанные уязвимости

ubuntu
больше 11 лет назад

OpenStack keystonemiddleware (formerly python-keystoneclient) 0.x before 0.11.0 and 1.x before 1.2.0 disables certification verification when the "insecure" option is set in a paste configuration (paste.ini) file regardless of the value, which allows remote attackers to conduct man-in-the-middle attacks via a crafted certificate.

redhat
больше 11 лет назад

OpenStack keystonemiddleware (formerly python-keystoneclient) 0.x before 0.11.0 and 1.x before 1.2.0 disables certification verification when the "insecure" option is set in a paste configuration (paste.ini) file regardless of the value, which allows remote attackers to conduct man-in-the-middle attacks via a crafted certificate.

nvd
больше 11 лет назад

OpenStack keystonemiddleware (formerly python-keystoneclient) 0.x before 0.11.0 and 1.x before 1.2.0 disables certification verification when the "insecure" option is set in a paste configuration (paste.ini) file regardless of the value, which allows remote attackers to conduct man-in-the-middle attacks via a crafted certificate.

debian
больше 11 лет назад

OpenStack keystonemiddleware (formerly python-keystoneclient) 0.x befo ...

EPSS

Процентиль: 58%
0.00365
Низкий

8.2 High

CVSS4

5.9 Medium

CVSS3

Дефекты

CWE-295