-----------
Title: Missing SSL certificate check in Python glance client
Reporter: Thomas Leaman (HP)
Products: Glance
Affects: All versions
Description:
Thomas Leaman from HP reported that the Python Glance client was failing to properly check certificates during the establishment of HTTPS connections. A remote attacker with access over segments of the network between client and server could potentially set up a man-in-the-middle attack and access the contents of the Glance client request (or response).
------------
Proposed impact description:
-----------
Title: Missing SSL certificate check in Python glance client
Reporter: Thomas Leaman (HP)
Products: Glance
Affects: All versions
Description:
Thomas Leaman from HP reported that the Python Glance client was failing to properly check certificates during the establishment of HTTPS connections. A remote attacker with access over segments of the network between client and server could potentially set up a man-in-the-middle attack and access the contents of the Glance client request (or response).
------------