CVE Vulnerabilities

CVE-2013-6396

Published: Feb 18, 2014 | Modified: Apr 11, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:N
RedHat/V2
4.3 MODERATE
AV:N/AC:M/Au:N/C:N/I:P/A:N
RedHat/V3
Ubuntu
LOW
root.io minimus.io echohq.com

The OpenStack Python client library for Swift (python-swiftclient) 1.0 through 1.9.0 does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

Affected Software

Name Vendor Start Version End Version
Swift Openstack 1.0.0 (including) 1.0.0 (including)
Swift Openstack 1.0.1 (including) 1.0.1 (including)
Swift Openstack 1.0.2 (including) 1.0.2 (including)
Swift Openstack 1.1.0 (including) 1.1.0 (including)
Swift Openstack 1.1.0-rc1 (including) 1.1.0-rc1 (including)
Swift Openstack 1.1.0-rc2 (including) 1.1.0-rc2 (including)
Swift Openstack 1.2.0 (including) 1.2.0 (including)
Swift Openstack 1.2.0-gamma1 (including) 1.2.0-gamma1 (including)
Swift Openstack 1.2.0-rc1 (including) 1.2.0-rc1 (including)
Swift Openstack 1.3.0 (including) 1.3.0 (including)
Swift Openstack 1.3.0-gamma1 (including) 1.3.0-gamma1 (including)
Swift Openstack 1.3.0-rc1 (including) 1.3.0-rc1 (including)
Swift Openstack 1.4.0 (including) 1.4.0 (including)
Swift Openstack 1.4.1 (including) 1.4.1 (including)
Swift Openstack 1.4.2 (including) 1.4.2 (including)
Swift Openstack 1.4.3 (including) 1.4.3 (including)
Swift Openstack 1.4.4 (including) 1.4.4 (including)
Swift Openstack 1.4.5 (including) 1.4.5 (including)
Swift Openstack 1.4.6 (including) 1.4.6 (including)
Swift Openstack 1.4.7 (including) 1.4.7 (including)
Swift Openstack 1.4.8 (including) 1.4.8 (including)
Swift Openstack 1.5.0 (including) 1.5.0 (including)
Swift Openstack 1.6.0 (including) 1.6.0 (including)
Swift Openstack 1.7.0 (including) 1.7.0 (including)
Swift Openstack 1.7.2 (including) 1.7.2 (including)
Swift Openstack 1.7.4 (including) 1.7.4 (including)
Swift Openstack 1.7.5 (including) 1.7.5 (including)
Swift Openstack 1.7.6 (including) 1.7.6 (including)
Swift Openstack 1.8.0 (including) 1.8.0 (including)
Swift Openstack 1.8.0-rc1 (including) 1.8.0-rc1 (including)
Swift Openstack 1.8.0-rc2 (including) 1.8.0-rc2 (including)
Swift Openstack 1.9.0 (including) 1.9.0 (including)
Swift Openstack 1.10.0 (including) 1.10.0 (including)
Swift Openstack 1.11.0 (including) 1.11.0 (including)
Python-swiftclient Ubuntu saucy *

References