Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

John Kinsella

#28669de 53,633
8.8CVSS total
Vulnerabilidades · 2
Baixa
1
Média
1
PT-2016-3608
6.0
2016-02-08
Apache · Apache Cloudstack · CVE-2015-3252
**Name of the Vulnerable Software and Affected Versions** Apache CloudStack versions prior to 4.5.2 **Description** The issue allows remote attackers to gain access by connecting to the VNC server due to improper preservation of VNC passwords when migrating KVM virtual machines. **Recommendations** For versions prior to 4.5.2, update to version 4.5.2 or later to resolve the issue. As a temporary workaround, consider restricting access to the VNC server to minimize the risk of exploitation.
PT-2014-3102
2.8
2014-01-14
Apache · Apache Cloudstack · CVE-2013-6398
**Name of the Vulnerable Software and Affected Versions** Apache CloudStack versions prior to 4.2.1 **Description** The issue allows remote attackers to bypass intended restrictions in firewall rules after the virtual router has been restarted, due to the failure of preserving source restrictions. **Recommendations** For versions prior to 4.2.1, update to version 4.2.1 or later to resolve the issue.