PT-2013-1611 · Eucalyptus · Eucalyptus
Publicado
2013-03-08
·
Atualizado
2013-03-18
·
CVE-2012-4066
CVSS v2.0
5.0
Média
| Vetor | AV:N/AC:L/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Eucalyptus versions 3.2.0 and earlier
Description
The internal message protocol for Walrus in Eucalyptus does not require signatures for unspecified request headers, allowing attackers to delete or upload snapshots.
Recommendations
For versions 3.2.0 and earlier, consider restricting access to the Walrus internal message protocol until a fix is available. As a temporary workaround, review and monitor all snapshot uploads and deletions to minimize the risk of exploitation.
Correção
Improper Authentication
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Eucalyptus