Vulnerabilities
Vulnerable Software
Apache:  >> Libcloud  Security Vulnerabilities
Libcloud 0.12.3 through 0.13.2 does not set the scrub_data parameter for the destroy DigitalOcean API, which allows local users to obtain sensitive information by leveraging a new VM.
CVSS Score
2.1
EPSS Score
0.005
Published
2014-01-07
Apache Libcloud before 0.11.1 uses an incorrect regular expression during verification of whether the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via a crafted certificate.
CVSS Score
5.9
EPSS Score
0.003
Published
2012-11-04
libcloud before 0.4.1 does not verify SSL certificates for HTTPS connections, which allows remote attackers to spoof certificates and bypass intended access restrictions via a man-in-the-middle (MITM) attack.
CVSS Score
4.3
EPSS Score
0.002
Published
2011-09-12


Contact Us

Shodan ® - All rights reserved