CVE-2010-4340

libcloud before 0.4.1 does not verify SSL certificates for HTTPS connections, which allows remote attackers to spoof certificates and bypass intended access restrictions via a man-in-the-middle (MITM) attack.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:apache:libcloud:*:*:*:*:*:*:*:*
cpe:2.3:a:apache:libcloud:0.2.0:*:*:*:*:*:*:*
cpe:2.3:a:apache:libcloud:0.3.0:*:*:*:*:*:*:*
cpe:2.3:a:apache:libcloud:0.3.1:*:*:*:*:*:*:*

History

No history.

Information

Published : 2011-09-12 12:41

Updated : 2024-02-04 17:54


NVD link : CVE-2010-4340

Mitre link : CVE-2010-4340

CVE.ORG link : CVE-2010-4340


JSON object : View

Products Affected

apache

  • libcloud
CWE
CWE-264

Permissions, Privileges, and Access Controls