← Back

Libcloud

libcloud

Vendor: Apache • 3 CVEs

CVEs (3)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Apache
1Libcloud
Apr 29, 2026
Jan 7, 2014
N/A· v4
N/A· v3
2.1 LOW· v2
Libcloud 0.12.3 through 0.13.2 does not set the scrub_data parameter for the destroy DigitalOcean API, which allows local users to obtain sensitive information by leveraging a new VM.
1Apache
1Libcloud
Apr 29, 2026
Nov 4, 2012
N/A· v4
5.9 MEDIUM· v3
5.8 MEDIUM· v2
Apache Libcloud before 0.11.1 uses an incorrect regular expression during verification of whether the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certifica...Show more
Apache Libcloud before 0.11.1 uses an incorrect regular expression during verification of whether the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via a crafted certificate.Show less
1Apache
1Libcloud
Apr 29, 2026
Sep 12, 2011
N/A· v4
N/A· v3
4.3 MEDIUM· v2
libcloud before 0.4.1 does not verify SSL certificates for HTTPS connections, which allows remote attackers to spoof certificates and bypass intended access restrictions via a man-in-the-middle (MITM) attack.