Vulnerability Database

289,697

Total vulnerabilities in the database

CVE-2013-6396

The OpenStack Python client library for Swift (python-swiftclient) 1.0 through 1.9.0 does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

  • Published: Feb 18, 2014
  • Updated: Apr 13, 2023
  • CVE: CVE-2013-6396
  • Severity: Medium
  • Exploit:

CVSS v2:

  • Severity: Medium
  • Score: 5.8
  • AV:N/AC:M/Au:N/C:P/I:P/A:N

CWEs:

Software From Fixed in
openstack / swift 1.8.0-rc1 1.8.0-rc1.x
openstack / swift 1.1.0-rc1 1.1.0-rc1.x
openstack / swift 1.4.6 1.4.6.x
openstack / swift 1.2.0 1.2.0.x
openstack / swift 1.4.4 1.4.4.x
openstack / swift 1.0.2 1.0.2.x
openstack / swift 1.9.0 1.9.0.x
openstack / swift 1.3.0-rc1 1.3.0-rc1.x
openstack / swift 1.4.1 1.4.1.x
openstack / swift 1.8.0-rc2 1.8.0-rc2.x
openstack / swift 1.0.1 1.0.1.x
openstack / swift 1.7.4 1.7.4.x
openstack / swift 1.2.0-gamma1 1.2.0-gamma1.x
openstack / swift 1.8.0 1.8.0.x
openstack / swift 1.7.2 1.7.2.x
openstack / swift 1.7.6 1.7.6.x
openstack / swift 1.4.0 1.4.0.x
openstack / swift 1.3.0 1.3.0.x
openstack / swift 1.4.3 1.4.3.x
openstack / swift 1.2.0-rc1 1.2.0-rc1.x
openstack / swift 1.10.0 1.10.0.x
openstack / swift 1.6.0 1.6.0.x
openstack / swift 1.11.0 1.11.0.x
openstack / swift 1.4.7 1.4.7.x
openstack / swift 1.1.0-rc2 1.1.0-rc2.x
openstack / swift 1.4.8 1.4.8.x
openstack / swift 1.4.2 1.4.2.x
openstack / swift 1.0.0 1.0.0.x
openstack / swift 1.4.5 1.4.5.x
openstack / swift 1.1.0 1.1.0.x
openstack / swift 1.3.0-gamma1 1.3.0-gamma1.x
openstack / swift 1.5.0 1.5.0.x
openstack / swift 1.7.5 1.7.5.x
openstack / swift 1.7.0 1.7.0.x