PT-2018-4100 · Apache · Apache Cloudstack
Ahmad Emneina
·
Published
2018-02-06
·
Updated
2018-02-26
·
CVE-2013-4317
CVSS v2.0
4.0
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Apache CloudStack versions 4.1.0 through 4.1.1
Description
The issue allows a regular, non-administrative user to see information for accounts other than their own when calling the "listProjectAccounts" API endpoint.
Recommendations
For Apache CloudStack versions 4.1.0 and 4.1.1, consider restricting access to the "listProjectAccounts" API endpoint until a patch is available.
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apache Cloudstack