CVE-2010-4340

libcloud before 0.4.1 does not verify SSL certificates for HTTPS connections, which allows remote attackers to spoof certificates and bypass intended access restrictions via a man-in-the-middle (MITM) attack.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:apache:libcloud:*:*:*:*:*:*:*:*
cpe:2.3:a:apache:libcloud:0.2.0:*:*:*:*:*:*:*
cpe:2.3:a:apache:libcloud:0.3.0:*:*:*:*:*:*:*
cpe:2.3:a:apache:libcloud:0.3.1:*:*:*:*:*:*:*

History

21 Nov 2024, 01:20

Type Values Removed Values Added
References () http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=598463 - () http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=598463 -
References () http://mail-archives.apache.org/mod_mbox/incubator-libcloud/201009.mbox/%3C5860913.463891285776633273.JavaMail.jira%40thor%3E - () http://mail-archives.apache.org/mod_mbox/incubator-libcloud/201009.mbox/%3C5860913.463891285776633273.JavaMail.jira%40thor%3E -
References () http://mail-archives.apache.org/mod_mbox/incubator-libcloud/201011.mbox/browser - () http://mail-archives.apache.org/mod_mbox/incubator-libcloud/201011.mbox/browser -
References () http://wiki.apache.org/incubator/LibcloudSSL - () http://wiki.apache.org/incubator/LibcloudSSL -
References () https://issues.apache.org/jira/browse/LIBCLOUD-55 - () https://issues.apache.org/jira/browse/LIBCLOUD-55 -

07 Nov 2023, 02:06

Type Values Removed Values Added
References
  • {'url': 'http://mail-archives.apache.org/mod_mbox/incubator-libcloud/201009.mbox/%3C5860913.463891285776633273.JavaMail.jira@thor%3E', 'name': '[libcloud] 20100929 [jira] Closed: (LIBCLOUD-55) this python project is vulnerable to MITM as it fails to verify the ssl validity of the remote destination.', 'tags': [], 'refsource': 'MLIST'}
  • () http://mail-archives.apache.org/mod_mbox/incubator-libcloud/201009.mbox/%3C5860913.463891285776633273.JavaMail.jira%40thor%3E -

Information

Published : 2011-09-12 12:41

Updated : 2024-11-21 01:20


NVD link : CVE-2010-4340

Mitre link : CVE-2010-4340

CVE.ORG link : CVE-2010-4340


JSON object : View

Products Affected

apache

  • libcloud
CWE
CWE-264

Permissions, Privileges, and Access Controls