QID 997511
Date Published: 2024-02-26
QID 997511: Python (Pip) Security Update for apache-libcloud (GHSA-w3j6-8j34-q43x)
libcloud before 0.4.1 does not verify SSL certificates for HTTPS connections, which allows remote attackers to spoof certificates and bypass intended access restrictions via a man-in-the-middle (MITM) attack. This is due to an upstream issue with python's SSL module rather than directly with libcloud.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-w3j6-8j34-q43x for updates and patch information.
Vendor References
- GHSA-w3j6-8j34-q43x -
github.com/advisories/GHSA-w3j6-8j34-q43x
CVEs related to QID 997511
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-w3j6-8j34-q43x | apache-libcloud |
|