CVE-2013-6396
published 2014-02-18CVE-2013-6396: The OpenStack Python client library for Swift (python-swiftclient) 1.0 through 1.9.0 does not verify X.509 certificates from SSL servers, which allows…
PriorityP423medium5.8CVSS 2.0
AVNACMAuNCPIPAN
EPSS
0.73%
50.3th percentile
The OpenStack Python client library for Swift (python-swiftclient) 1.0 through 1.9.0 does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
Affected
27 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | python-swiftclient | < python-swiftclient 1:2.0.2-1 (bookworm) | python-swiftclient 1:2.0.2-1 (bookworm) |
| openstack | swift | — | — |
| openstack | swift | — | — |
| openstack | swift | — | — |
| openstack | swift | — | — |
| openstack | swift | — | — |
| openstack | swift | — | — |
| openstack | swift | — | — |
| openstack | swift | — | — |
| openstack | swift | — | — |
| openstack | swift | — | — |
| openstack | swift | — | — |
| openstack | swift | — | — |
| openstack | swift | — | — |
| openstack | swift | — | — |
| openstack | swift | — | — |
| openstack | swift | — | — |
| openstack | swift | — | — |
| openstack | swift | — | — |
| openstack | swift | — | — |
| openstack | swift | — | — |
| openstack | swift | — | — |
| openstack | swift | — | — |
| openstack | swift | — | — |
| openstack | swift | — | — |
CVSS provenance
nvdv2.05.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:N
osv5.8MEDIUM
vendor_debian5.8MEDIUM
vendor_redhat5.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
python-swiftclient: SSL certificate verification security issue
vendor_redhat·2013-07-10·CVSS 5.8
CVE-2013-6396 [MEDIUM] python-swiftclient: SSL certificate verification security issue
python-swiftclient: SSL certificate verification security issue
The OpenStack Python client library for Swift (python-swiftclient) 1.0 through 1.9.0 does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
Statement: The Red Hat Security Response Team has rated this issue as having Moderate security impact in Red Hat Enterprise Linux OpenStack Platform 3 however fixing this issue would require a change to default behavior. This issue is not currently planned to be addressed in future updates. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.
Package: python-swiftclient (Red Hat OpenStack Platfo
Debian
CVE-2013-6396: python-swiftclient - The OpenStack Python client library for Swift (python-swiftclient) 1.0 through 1...
vendor_debian·2013·CVSS 5.8
CVE-2013-6396 [MEDIUM] CVE-2013-6396: python-swiftclient - The OpenStack Python client library for Swift (python-swiftclient) 1.0 through 1...
The OpenStack Python client library for Swift (python-swiftclient) 1.0 through 1.9.0 does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
Scope: local
bookworm: resolved (fixed in 1:2.0.2-1)
bullseye: resolved (fixed in 1:2.0.2-1)
forky: resolved (fixed in 1:2.0.2-1)
sid: resolved (fixed in 1:2.0.2-1)
trixie: resolved (fixed in 1:2.0.2-1)
OSV
Python Swift client is vulnerable to Missing SSL Certificate Check
osv·2022-05-17
CVE-2013-6396 [CRITICAL] Python Swift client is vulnerable to Missing SSL Certificate Check
Python Swift client is vulnerable to Missing SSL Certificate Check
The OpenStack Python client library for Swift (python-swiftclient) from 1.0 before 2.0 does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
GHSA
Python Swift client is vulnerable to Missing SSL Certificate Check
ghsa·2022-05-17
CVE-2013-6396 [CRITICAL] CWE-295 Python Swift client is vulnerable to Missing SSL Certificate Check
Python Swift client is vulnerable to Missing SSL Certificate Check
The OpenStack Python client library for Swift (python-swiftclient) from 1.0 before 2.0 does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
OSV
CVE-2013-6396: The OpenStack Python client library for Swift (python-swiftclient) 1
osv·2014-02-18·CVSS 5.8
CVE-2013-6396 [MEDIUM] CVE-2013-6396: The OpenStack Python client library for Swift (python-swiftclient) 1
The OpenStack Python client library for Swift (python-swiftclient) 1.0 through 1.9.0 does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
No detection rules found.
No public exploits indexed.
2014-02-18
Published