← Back

CVE-2013-4111

nvd nist
Published: Aug 28, 2013Modified: Apr 29, 2026

JSON object

Loading...
5.8
Vector
AV:N/AC:M/Au:N/C:P/I:P/A:N
Exploitability: 8.6 / Impact: 4.9
Source: NVD

Description

The Python client library for Glance (python-glanceclient) before 0.10.0 does not properly check the preverify_ok value, which prevents the server hostname from being verified with a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate and allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.

Affected (2)

1 product
Python Glanceclient
1 product
Opensuse
Configuration A
2 vulnerable · 8 platform
Vulnerable SoftwareAffected Versions
Version 0.9.0
Version 12.3
Running on/withPlatform Versions
Openstack
Python Glanceclient
Version 0.4.0
Openstack
Python Glanceclient
Version 0.4.1
Openstack
Python Glanceclient
Version 0.4.2
Openstack
Python Glanceclient
Version 0.5.0
Openstack
Python Glanceclient
Version 0.5.1
Openstack
Python Glanceclient
Version 0.6.0
Openstack
Python Glanceclient
Version 0.7.0
Openstack
Python Glanceclient
Version 0.8.0

References (14)

Source: secalert@redhat.com
Vendor Advisory
Source: secalert@redhat.com
Vendor Advisory
Source: secalert@redhat.com
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.