CVE-2010-4340 Information
Feb 14, 2021
cve
Description
libcloud before 0.4.1 does not verify SSL certificates for HTTPS connections which allows remote attackers to spoof certificates and bypass intended access restrictions via a man-in-the-middle (MITM) attack.
Reference
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=598463 http://mail-archives.apache.org/mod_mbox/incubator-libcloud/201009.mbox/3C5860913.463891285776633273.JavaMail.jira@thor3E http://mail-archives.apache.org/mod_mbox/incubator-libcloud/201011.mbox/browser http://wiki.apache.org/incubator/LibcloudSSL https://issues.apache.org/jira/browse/LIBCLOUD-55
Share on: