Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-w3j6-8j34-q43x

Опубликовано: 17 мая 2022
Источник: github
Github: Прошло ревью
CVSS4: 8.7
CVSS3: 7.5

Описание

Apache Libcloud does not verify SSL certificates for HTTPS connections

libcloud before 0.4.0 does not verify SSL certificates for HTTPS connections, which allows remote attackers to spoof certificates and bypass intended access restrictions via a man-in-the-middle (MITM) attack. This is due to an upstream issue with python's SSL module rather than directly with libcloud.

Пакеты

Наименование

apache-libcloud

pip
Затронутые версииВерсия исправления

< 0.4.0

0.4.0

EPSS

Процентиль: 41%
0.00185
Низкий

8.7 High

CVSS4

7.5 High

CVSS3

Дефекты

CWE-295

Связанные уязвимости

ubuntu
больше 14 лет назад

libcloud before 0.4.1 does not verify SSL certificates for HTTPS connections, which allows remote attackers to spoof certificates and bypass intended access restrictions via a man-in-the-middle (MITM) attack.

nvd
больше 14 лет назад

libcloud before 0.4.1 does not verify SSL certificates for HTTPS connections, which allows remote attackers to spoof certificates and bypass intended access restrictions via a man-in-the-middle (MITM) attack.

debian
больше 14 лет назад

libcloud before 0.4.1 does not verify SSL certificates for HTTPS conne ...

EPSS

Процентиль: 41%
0.00185
Низкий

8.7 High

CVSS4

7.5 High

CVSS3

Дефекты

CWE-295