PT-2019-12820 · Onapp · Onapp
Published
2019-06-19
·
Updated
2020-08-24
·
CVE-2019-12491
CVSS v2.0
8.5
High
| Vector | AV:N/AC:M/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
OnApp versions prior to 5.0.0-88
OnApp versions prior to 5.5.0-93
OnApp versions prior to 6.0.0-196
Description
The issue allows an attacker to run arbitrary commands with root privileges on servers managed by OnApp for XEN/KVM hypervisors. An attacker must have control of a single server on a given cloud, which can be achieved by renting one. From the source server, the attacker can craft any command and trigger the OnApp platform to execute that command with root privileges on a target server.
Recommendations
For versions prior to 5.0.0-88, update to version 5.0.0-88 or later.
For versions prior to 5.5.0-93, update to version 5.5.0-93 or later.
For versions prior to 6.0.0-196, update to version 6.0.0-196 or later.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Onapp