PT-2018-5014 · Hewlett Packard · Hpe Helion Eucalyptus
Publicado
2018-02-15
·
Atualizado
2018-03-13
·
CVE-2016-8520
CVSS v3.1
8.8
Alta
| Vetor | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
HPE Helion Eucalyptus versions 4.3.0 and earlier
Description
The issue arises from incorrect permission checks for IAM users accessing versioned objects and ACLs. As a result, authenticated users with S3 permissions may also be able to access versioned data.
Recommendations
For HPE Helion Eucalyptus versions 4.3.0 and earlier, consider restricting access to versioned objects and ACLs to prevent unauthorized data access until a fix is available.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Hpe Helion Eucalyptus