{"id":"GHSA-p3xv-97g8-4wmj","summary":"Python Swift client is vulnerable to Missing SSL Certificate Check","details":"The OpenStack Python client library for Swift (python-swiftclient) from 1.0 before 2.0 does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.","aliases":["CVE-2013-6396","PYSEC-2014-12"],"modified":"2025-07-07T13:17:33.756412Z","published":"2022-05-17T04:52:37Z","database_specific":{"cwe_ids":["CWE-295"],"severity":"CRITICAL","github_reviewed":true,"github_reviewed_at":"2023-08-29T18:56:11Z","nvd_published_at":"2014-02-18T19:55:00Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2013-6396"},{"type":"WEB","url":"https://github.com/openstack/python-swiftclient/commit/b182112719ab87942472e44aa3446ea0eb19a289"},{"type":"WEB","url":"https://bugs.launchpad.net/python-swiftclient/+bug/1199783"},{"type":"PACKAGE","url":"https://github.com/chmouel/python-swiftclient"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/python-swiftclient/PYSEC-2014-12.yaml"},{"type":"WEB","url":"https://review.opendev.org/c/openstack/python-swiftclient/+/69187"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2014/02/17/7"}],"affected":[{"package":{"name":"python-swiftclient","ecosystem":"PyPI","purl":"pkg:pypi/python-swiftclient"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"1.0"},{"fixed":"2.0"}]}],"versions":["1.0","1.1.1","1.2.0","1.3.0","1.4.0","1.5.0","1.6.0","1.7.0","1.8.0","1.9.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-p3xv-97g8-4wmj/GHSA-p3xv-97g8-4wmj.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N"}]}