The internal message protocol for Walrus in Eucalyptus 3.2.0 and earlier does not require signatures for unspecified request headers, which allows attackers to (1) delete or (2) upload snapshots.
References
| Link | Resource |
|---|---|
| http://www.eucalyptus.com/eucalyptus-cloud/security/esa-08 | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
Information
Published : 2013-03-08 10:55
Updated : 2013-03-17 21:00
NVD link : CVE-2012-4066
Mitre link : CVE-2012-4066
JSON object : View
CWE
CWE-287
Improper Authentication
Products Affected
eucalyptus
- eucalyptus


