QID 996741
Date Published: 2024-01-17
QID 996741: Python (Pip) Security Update for apache-libcloud (GHSA-prcq-52f8-fp44)
Apache Libcloud before 0.11.1 uses an incorrect regular expression during verification of whether the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via a crafted certificate.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-prcq-52f8-fp44 for updates and patch information.
Vendor References
- GHSA-prcq-52f8-fp44 -
github.com/advisories/GHSA-prcq-52f8-fp44
CVEs related to QID 996741
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-prcq-52f8-fp44 | apache-libcloud |
|