PT-2011-2591 · Eucalyptus · Eucalyptus Ee+1
Dave Walker
+1
·
Published
2011-06-02
·
Updated
2018-11-29
·
CVE-2011-0730
CVSS v2.0
6.5
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Eucalyptus versions prior to 2.0.3
Eucalyptus EE versions prior to 2.0.2
Description
The issue is related to the improper interpretation of signed elements in SOAP requests, which can be exploited by man-in-the-middle attackers to execute arbitrary commands by modifying a request. This is related to an "XML Signature Element Wrapping" or a "SOAP signature replay" issue.
Recommendations
For Eucalyptus versions prior to 2.0.3, update to version 2.0.3 or later.
For Eucalyptus EE versions prior to 2.0.2, update to version 2.0.2 or later.
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Eucalyptus
Eucalyptus Ee