In fence-agents before 4.0.17 does not verify remote SSL certificates in the fenceciscoucs.py script which can potentially allow for man-in-the-middle attackers to spoof SSL servers via arbitrary SSL certificates.
{ "urgency": "low" }
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2014-0104.json"