ovirt-engine-sdk@3.2.0.5-SNAPSHOT vulnerabilities

A SDK interface to oVirt Virtualization

  • latest version

    3.2.0.5-SNAPSHOT

  • first published

    11 years ago

  • latest version published

    11 years ago

  • licenses detected

  • Direct Vulnerabilities

    Known vulnerabilities in the ovirt-engine-sdk package. This does not include vulnerabilities belonging to this package’s dependencies.

    How to fix?

    Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.

    Fix for free
    VulnerabilityVulnerable Version
    • M
    Man-in-the-Middle (MitM)

    ovirt-engine-sdk is a SDK interface to oVirt Virtualization.

    Affected versions of this package are vulnerable to Man-in-the-Middle (MitM).
    It was reported that oVirt's Python SDK does not verify that the hostname of the remote endpoint matches the Common Name (CN) or subjectAltName as specified by its x.509 certificate in a TLS/SSL session. This could allow man-in-the-middle attackers to spoof remote endpoints via an arbitrary yet valid certificate.

    [,3.3.0.3)