PYSEC-2011-24

See a problem?
Import Source
https://github.com/pypa/advisory-database/blob/main/vulns/apache-libcloud/PYSEC-2011-24.yaml
JSON Data
https://api.osv.dev/v1/vulns/PYSEC-2011-24
Aliases
Published
2011-09-12T12:41:00Z
Modified
2024-02-23T21:28:23.201015Z
Summary
[none]
Details

libcloud before 0.4.1 does not verify SSL certificates for HTTPS connections, which allows remote attackers to spoof certificates and bypass intended access restrictions via a man-in-the-middle (MITM) attack.

References

Affected packages

PyPI / apache-libcloud

Package

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.4.2

Affected versions

0.*

0.3.1
0.4.0