PT-2018-5014 · Hewlett Packard · Hpe Helion Eucalyptus

Publicado

2018-02-15

·

Atualizado

2018-03-13

·

CVE-2016-8520

CVSS v3.1

8.8

Alta

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions HPE Helion Eucalyptus versions 4.3.0 and earlier
Description The issue arises from incorrect permission checks for IAM users accessing versioned objects and ACLs. As a result, authenticated users with S3 permissions may also be able to access versioned data.
Recommendations For HPE Helion Eucalyptus versions 4.3.0 and earlier, consider restricting access to versioned objects and ACLs to prevent unauthorized data access until a fix is available.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2016-8520

Produtos afetados

Hpe Helion Eucalyptus