CVE Vulnerabilities

CVE-2010-4340

Published: Sep 12, 2011 | Modified: Apr 11, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu
LOW
root.io logo minimus.io logo echo.ai logo

libcloud before 0.4.1 does not verify SSL certificates for HTTPS connections, which allows remote attackers to spoof certificates and bypass intended access restrictions via a man-in-the-middle (MITM) attack.

Affected Software

NameVendorStart VersionEnd Version
LibcloudApache*0.4.0 (including)
LibcloudApache0.2.0 (including)0.2.0 (including)
LibcloudApache0.3.0 (including)0.3.0 (including)
LibcloudApache0.3.1 (including)0.3.1 (including)
LibcloudUbuntulucid*
LibcloudUbuntumaverick*
LibcloudUbuntunatty*
LibcloudUbuntuupstream*

References