CVE Vulnerabilities

CVE-2012-4066

Improper Authentication

Published: Mar 08, 2013 | Modified: Mar 18, 2013
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu

The internal message protocol for Walrus in Eucalyptus 3.2.0 and earlier does not require signatures for unspecified request headers, which allows attackers to (1) delete or (2) upload snapshots.

Weakness

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Affected Software

Name Vendor Start Version End Version
Eucalyptus Eucalyptus 1.1 1.1
Eucalyptus Eucalyptus 1.6 1.6
Eucalyptus Eucalyptus 3.0.1 3.0.1
Eucalyptus Eucalyptus 1.5.2 1.5.2
Eucalyptus Eucalyptus 1.2 1.2
Eucalyptus Eucalyptus 1.5.1 1.5.1
Eucalyptus Eucalyptus 3.1.0 3.1.0
Eucalyptus Eucalyptus 2.0.3 2.0.3
Eucalyptus Eucalyptus 2.0 2.0
Eucalyptus Eucalyptus 3.0 3.0
Eucalyptus Eucalyptus * 3.2.0
Eucalyptus Eucalyptus 1.4 1.4
Eucalyptus Eucalyptus 2.0.0 2.0.0
Eucalyptus Eucalyptus 2.0.2 2.0.2
Eucalyptus Eucalyptus 1.0 1.0
Eucalyptus Eucalyptus 1.6.2 1.6.2
Eucalyptus Eucalyptus 1.3 1.3
Eucalyptus Eucalyptus 2.0.1 2.0.1

Potential Mitigations

References