Skip to content

python-glanceclient vulnerable to SSL server spoofing due to unverified X.509 certificate

Moderate severity GitHub Reviewed Published May 14, 2022 to the GitHub Advisory Database • Updated Feb 13, 2023

Package

pip python-glanceclient (pip)

Affected versions

< 0.10.0

Patched versions

0.10.0

Description

The Python client library for Glance (python-glanceclient) before 0.10.0 does not properly check the preverify_ok value, which prevents the server hostname from being verified with a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate and allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.

References

Published by the National Vulnerability Database Aug 28, 2013
Published to the GitHub Advisory Database May 14, 2022
Reviewed Feb 6, 2023
Last updated Feb 13, 2023

Severity

Moderate

Weaknesses

CVE ID

CVE-2013-4111

GHSA ID

GHSA-qgfg-gvff-523v
Checking history
See something to contribute? Suggest improvements for this vulnerability.