Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2013-6396

Опубликовано: 10 июл. 2013
Источник: redhat
CVSS2: 4.3

Описание

The OpenStack Python client library for Swift (python-swiftclient) 1.0 through 1.9.0 does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

Отчет

The Red Hat Security Response Team has rated this issue as having Moderate security impact in Red Hat Enterprise Linux OpenStack Platform 3 however fixing this issue would require a change to default behavior. This issue is not currently planned to be addressed in future updates. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat OpenStack Platform 3python-swiftclientAffected
Red Hat OpenStack Platform 4python-swiftclientAffected

Показывать по

Дополнительная информация

Статус:

Moderate
https://bugzilla.redhat.com/show_bug.cgi?id=1031652python-swiftclient: SSL certificate verification security issue

4.3 Medium

CVSS2

Связанные уязвимости

ubuntu
почти 12 лет назад

The OpenStack Python client library for Swift (python-swiftclient) 1.0 through 1.9.0 does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

nvd
почти 12 лет назад

The OpenStack Python client library for Swift (python-swiftclient) 1.0 through 1.9.0 does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

debian
почти 12 лет назад

The OpenStack Python client library for Swift (python-swiftclient) 1.0 ...

CVSS3: 9.1
github
больше 3 лет назад

Python Swift client is vulnerable to Missing SSL Certificate Check

4.3 Medium

CVSS2