4.12.0
14 years ago
3 months ago
Known vulnerabilities in the python-glanceclient package. This does not include vulnerabilities belonging to this package’s dependencies.
Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.
Fix for free| Vulnerability | Vulnerable Version |
|---|---|
Affected versions of this package are vulnerable to Man-in-the-Middle (MitM) attacks. The Python client library for Glance (python-glanceclient) before 0.10.0 does not properly check the preverify_ok value, which prevents the server hostname from being verified with a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate and allows Man-in-the-Middle (MitM) attackers to spoof SSL servers via an arbitrary valid certificate. How to fix Man-in-the-Middle (MitM)? Upgrade to version | [,0.12.0) |