CVE-2013-6396: Critical severity Openstack Swift vulnerability
The OpenStack Python client library for Swift (python-swiftclient) 1.0 through 1.9.0 does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
Other sources
The OpenStack Python client library for Swift (python-swiftclient) from 1.0 before 2.0 does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
— GitHub
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
pip/python-swiftclientto a version that resolves this vulnerability.Fixed in 2.0
Event History
Frequently Asked Questions
What is the severity of CVE-2013-6396?
CVE-2013-6396 is rated as a high severity vulnerability due to its potential for man-in-the-middle attacks.
How do I fix CVE-2013-6396?
To fix CVE-2013-6396, upgrade python-swiftclient to version 2.0.2 or later.
What is the impact of CVE-2013-6396?
The impact of CVE-2013-6396 includes the risk of unauthorized access to sensitive information through spoofed SSL servers.
Which versions of python-swiftclient are affected by CVE-2013-6396?
CVE-2013-6396 affects python-swiftclient versions from 1.0 to 1.9.0.
Is CVE-2013-6396 present in OpenStack Swift3?
Yes, CVE-2013-6396 is present in several versions of OpenStack Swift3 prior to the fix.