Junglewise Threat Intelligence
CVE-2010-4340: PYSEC-2011-24 - libcloud before 0.4.1 does not verify SSL certificates for HTTPS connections, which allows remote attackers to spoof certificates and bypass
CVE-2010-4340 · Severity: low · CVSS 3.1 · Published 2011-09-12
Technologies: apache-libcloud (PyPI). Vendors: PyPI.
Executive brief
libcloud before 0.4.1 does not verify SSL certificates for HTTPS connections, which allows remote attackers to spoof certificates and bypass intended access restrictions via a man-in-the-middle (MITM) attack.