CVE Vulnerabilities

CVE-2015-6861

Published: Jan 05, 2016 | Modified: Apr 12, 2025
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
4.6 MEDIUM
AV:N/AC:H/Au:S/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

HPE Helion Eucalyptus 3.4.0 through 4.2.0 allows remote authenticated users to bypass an intended AssumeRole permission requirement and assume an IAM role by leveraging a policy setting for a users account.

Affected Software

NameVendorStart VersionEnd Version
EucalyptusEucalyptus3.4.0 (including)3.4.0 (including)
EucalyptusEucalyptus3.4.1 (including)3.4.1 (including)
EucalyptusEucalyptus3.4.2 (including)3.4.2 (including)
EucalyptusEucalyptus3.4.3 (including)3.4.3 (including)
EucalyptusEucalyptus4.0.0 (including)4.0.0 (including)
EucalyptusEucalyptus4.0.1 (including)4.0.1 (including)
EucalyptusEucalyptus4.0.2 (including)4.0.2 (including)
EucalyptusEucalyptus4.1.0 (including)4.1.0 (including)
EucalyptusEucalyptus4.1.1 (including)4.1.1 (including)
EucalyptusEucalyptus4.1.2 (including)4.1.2 (including)
EucalyptusEucalyptus4.2.0 (including)4.2.0 (including)

References