Описание
Apache Libcloud before 0.11.1 uses an incorrect regular expression during verification of whether the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via a crafted certificate.
Уязвимые конфигурации
EPSS
5.9 Medium
CVSS3
5.8 Medium
CVSS2
Дефекты
Связанные уязвимости
Apache Libcloud before 0.11.1 uses an incorrect regular expression during verification of whether the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via a crafted certificate.
Apache Libcloud before 0.11.1 uses an incorrect regular expression dur ...
Apache Libcloud vulnerable to certificate impersonation
EPSS
5.9 Medium
CVSS3
5.8 Medium
CVSS2