CVE Vulnerabilities

CVE-2015-6861

Published: Jan 05, 2016 | Modified: Nov 28, 2016
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
4.6 MEDIUM
AV:N/AC:H/Au:S/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

HPE Helion Eucalyptus 3.4.0 through 4.2.0 allows remote authenticated users to bypass an intended AssumeRole permission requirement and assume an IAM role by leveraging a policy setting for a users account.

Affected Software

Name Vendor Start Version End Version
Eucalyptus Eucalyptus 3.4.0 (including) 3.4.0 (including)
Eucalyptus Eucalyptus 3.4.1 (including) 3.4.1 (including)
Eucalyptus Eucalyptus 3.4.2 (including) 3.4.2 (including)
Eucalyptus Eucalyptus 3.4.3 (including) 3.4.3 (including)
Eucalyptus Eucalyptus 4.0.0 (including) 4.0.0 (including)
Eucalyptus Eucalyptus 4.0.1 (including) 4.0.1 (including)
Eucalyptus Eucalyptus 4.0.2 (including) 4.0.2 (including)
Eucalyptus Eucalyptus 4.1.0 (including) 4.1.0 (including)
Eucalyptus Eucalyptus 4.1.1 (including) 4.1.1 (including)
Eucalyptus Eucalyptus 4.1.2 (including) 4.1.2 (including)
Eucalyptus Eucalyptus 4.2.0 (including) 4.2.0 (including)

References