Lucene search

K
osvGoogleOSV:GHSA-W3J6-8J34-Q43X
HistoryMay 17, 2022 - 5:39 a.m.

Apache Libcloud does not verify SSL certificates for HTTPS connections

2022-05-1705:39:24
Google
osv.dev
2

7.1 High

AI Score

Confidence

Low

0.001 Low

EPSS

Percentile

48.2%

libcloud before 0.4.1 does not verify SSL certificates for HTTPS connections, which allows remote attackers to spoof certificates and bypass intended access restrictions via a man-in-the-middle (MITM) attack. This is due to an upstream issue with python’s SSL module rather than directly with libcloud.

7.1 High

AI Score

Confidence

Low

0.001 Low

EPSS

Percentile

48.2%