—
PYSEC-2014-12
Quick fix
PYSEC-2014-12 — python-swiftclient: upgrade to the fixed version with the command below.
pip install --upgrade 'python-swiftclient>=2.0'Details
The OpenStack Python client library for Swift (python-swiftclient) 1.0 through 1.9.0 does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
Are you affected?
Enter the version of the package you're using.
Affected packages
PyPI/python-swiftclient
Introduced in:
1.0Fixed in: 2.0Fix
pip install --upgrade 'python-swiftclient>=2.0'