Junglewise Threat Intelligence

CVE-2010-4340: PYSEC-2011-24 - libcloud before 0.4.1 does not verify SSL certificates for HTTPS connections, which allows remote attackers to spoof certificates and bypass

CVE-2010-4340 · Severity: low · CVSS 3.1 · Published 2011-09-12

Technologies: apache-libcloud (PyPI). Vendors: PyPI.

Executive brief

libcloud before 0.4.1 does not verify SSL certificates for HTTPS connections, which allows remote attackers to spoof certificates and bypass intended access restrictions via a man-in-the-middle (MITM) attack.

Affected products

  • PyPI apache-libcloud

Related threats