libcloud before 0.4.0 does not verify SSL certificates for HTTPS connections, which allows remote attackers to spoof certificates and bypass intended access restrictions via a man-in-the-middle (MITM) attack. This is due to an upstream issue with python's SSL module rather than directly with libcloud.
{ "nvd_published_at": "2011-09-12T12:41:00Z", "github_reviewed_at": "2024-02-23T20:59:34Z", "github_reviewed": true, "severity": "HIGH", "cwe_ids": [ "CWE-295" ] }