PT-2018-5014 · Hewlett Packard · Hpe Helion Eucalyptus
Published
2018-02-15
·
Updated
2018-03-13
·
CVE-2016-8520
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
HPE Helion Eucalyptus versions 4.3.0 and earlier
Description
The issue arises from incorrect permission checks for IAM users accessing versioned objects and ACLs. As a result, authenticated users with S3 permissions may also be able to access versioned data.
Recommendations
For HPE Helion Eucalyptus versions 4.3.0 and earlier, consider restricting access to versioned objects and ACLs to prevent unauthorized data access until a fix is available.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Hpe Helion Eucalyptus