{"id":"GHSA-w3j6-8j34-q43x","summary":"Apache Libcloud does not verify SSL certificates for HTTPS connections","details":"libcloud before 0.4.0 does not verify SSL certificates for HTTPS connections, which allows remote attackers to spoof certificates and bypass intended access restrictions via a man-in-the-middle (MITM) attack. This is due to an upstream issue with python's SSL module rather than directly with libcloud.","aliases":["CVE-2010-4340","PYSEC-2011-24"],"modified":"2024-09-13T14:37:26.441750Z","published":"2022-05-17T05:39:24Z","database_specific":{"cwe_ids":["CWE-295"],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2024-02-23T20:59:34Z","nvd_published_at":"2011-09-12T12:41:00Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2010-4340"},{"type":"WEB","url":"https://github.com/apache/libcloud/commit/87ee61e6ba03a43dcefea2ce180988bec066b6fd"},{"type":"WEB","url":"https://bugs.python.org/issue1589"},{"type":"PACKAGE","url":"https://github.com/apache/libcloud"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/apache-libcloud/PYSEC-2011-24.yaml"},{"type":"WEB","url":"https://issues.apache.org/jira/browse/LIBCLOUD-55"},{"type":"WEB","url":"http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=598463"},{"type":"WEB","url":"http://mail-archives.apache.org/mod_mbox/incubator-libcloud/201009.mbox/%3C5860913.463891285776633273.JavaMail.jira@thor%3E"},{"type":"WEB","url":"http://mail-archives.apache.org/mod_mbox/incubator-libcloud/201011.mbox/browser"},{"type":"WEB","url":"http://wiki.apache.org/incubator/LibcloudSSL"}],"affected":[{"package":{"name":"apache-libcloud","ecosystem":"PyPI","purl":"pkg:pypi/apache-libcloud"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.4.0"}]}],"versions":["0.3.1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-w3j6-8j34-q43x/GHSA-w3j6-8j34-q43x.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N"}]}