PT-2016-5362 · Apache · Apache Cloudstack
Publicado
2016-06-10
·
Atualizado
2018-10-09
·
CVE-2016-3085
CVSS v3.1
6.5
Média
| Vetor | AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Apache CloudStack versions 4.5.x through 4.5.2.1
Apache CloudStack versions 4.6.x through 4.6.2.1
Apache CloudStack versions 4.7.x through 4.7.1.1
Apache CloudStack versions 4.8.x through 4.8.0.1
Description
The issue allows remote attackers to bypass authentication and access the user interface when SAML-based authentication is enabled and used. This is related to vectors involving the SAML plugin.
Recommendations
For Apache CloudStack versions 4.5.x through 4.5.2.1, update to version 4.5.2.1 or later.
For Apache CloudStack versions 4.6.x through 4.6.2.1, update to version 4.6.2.1 or later.
For Apache CloudStack versions 4.7.x through 4.7.1.1, update to version 4.7.1.1 or later.
For Apache CloudStack versions 4.8.x through 4.8.0.1, update to version 4.8.0.1 or later.
Correção
Improper Authentication
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Apache Cloudstack