cbcvebase.
CVE-2010-4340
published 2011-09-12

CVE-2010-4340: libcloud before 0.4.1 does not verify SSL certificates for HTTPS connections, which allows remote attackers to spoof certificates and bypass intended access…

medium4.3CVSS 3.1
AVNACMAuNCNIPAN
libcloud before 0.4.1 does not verify SSL certificates for HTTPS connections, which allows remote attackers to spoof certificates and bypass intended access restrictions via a man-in-the-middle (MITM) attack.

Affected

9 ranges
VendorProductVersion rangeFixed in
apachelibcloud<= 0.4.0
apachelibcloud
apachelibcloud
apachelibcloud
apachelibcloud>= 0 < 0.5.0-10.5.0-1
apachelibcloud>= 0 < 0.5.0-10.5.0-1
apachelibcloud>= 0 < 0.5.0-10.5.0-1
apachelibcloud>= 0 < 0.5.0-10.5.0-1
debianlibcloud< libcloud 0.5.0-1 (bookworm)libcloud 0.5.0-1 (bookworm)

CVSS provenance

nvd4.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
osv4.3MEDIUM