PT-2018-4065 · Apache · Apache Vcl
Publicado
2018-02-21
·
Atualizado
2019-07-29
·
CVE-2013-0267
CVSS v2.0
6.5
Média
| Vetor | AV:N/AC:L/Au:S/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Apache VCL versions 2.1, 2.2.x through 2.2.1, 2.3.x through 2.3.1
Description
The issue allows remote authenticated users with certain permissions to gain privileges, cause a denial of service, or conduct cross-site scripting (XSS) attacks. This is due to improper data validation in the Privileges portion of the web GUI and the XMLRPC API.
Recommendations
For Apache VCL version 2.1, update to version 2.2.2 or later.
For Apache VCL versions 2.2.x through 2.2.1, update to version 2.2.2 or later.
For Apache VCL versions 2.3.x through 2.3.1, update to version 2.3.2 or later.
Correção
RCE
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Apache Vcl