DescriptionThe Python client library for Glance (python-glanceclient) before 0.10.0 does not properly check the preverify_ok value, which prevents the server hostname from being verified with a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate and allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.
Overall state of this security issue: Does not affect SUSE products
This issue is currently rated as having moderate severity.
|National Vulnerability Database|
- openSUSE-SU-2013:1330-1, published Wed, 14 Aug 2013 03:04:14 +0200 (CEST)
Status of this issue by product and package
Please note that this evaluation state might be work in progress, incomplete or outdated. Also information for service packs in the LTSS phase is only included for issues meeting the LTSS criteria. If in doubt, feel free to contact us for clarification.
|HPE Helion OpenStack 8||openstack-glance||Analysis|
|SUSE OpenStack Cloud 7||openstack-glance||Unsupported|
|SUSE OpenStack Cloud 8||openstack-glance||Analysis|
|SUSE OpenStack Cloud 9||openstack-glance||Analysis|
|SUSE OpenStack Cloud Crowbar 8||openstack-glance||Analysis|
|SUSE OpenStack Cloud Crowbar 9||openstack-glance||Analysis|