CVE-2010-4340

libcloud before 0.4.1 does not verify SSL certificates for HTTPS connections, which allows remote attackers to spoof certificates and bypass intended access restrictions via a man-in-the-middle (MITM) attack.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:apache:libcloud:*:*:*:*:*:*:*:*
cpe:2.3:a:apache:libcloud:0.2.0:*:*:*:*:*:*:*
cpe:2.3:a:apache:libcloud:0.3.0:*:*:*:*:*:*:*
cpe:2.3:a:apache:libcloud:0.3.1:*:*:*:*:*:*:*

History

07 Nov 2023, 02:06

Type Values Removed Values Added
References
  • {'url': 'http://mail-archives.apache.org/mod_mbox/incubator-libcloud/201009.mbox/%3C5860913.463891285776633273.JavaMail.jira@thor%3E', 'name': '[libcloud] 20100929 [jira] Closed: (LIBCLOUD-55) this python project is vulnerable to MITM as it fails to verify the ssl validity of the remote destination.', 'tags': [], 'refsource': 'MLIST'}
  • () http://mail-archives.apache.org/mod_mbox/incubator-libcloud/201009.mbox/%3C5860913.463891285776633273.JavaMail.jira%40thor%3E -

Information

Published : 2011-09-12 12:41

Updated : 2023-12-10 11:03


NVD link : CVE-2010-4340

Mitre link : CVE-2010-4340

CVE.ORG link : CVE-2010-4340


JSON object : View

Products Affected

apache

  • libcloud
CWE
CWE-264

Permissions, Privileges, and Access Controls