Apache Libcloud before 0.11.1 uses an incorrect regular expression during verification of whether the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via a crafted certificate.
Score: 0.0
Priority: Unclassified
Score: 0.00336
Percentile:
0.55807
CVSS v3.1 Score: 5.9
Severity: MEDIUM