The virtual router in Apache CloudStack before 4.2.1 does not preserve the source restrictions in firewall rules after being restarted, which allows remote attackers to bypass intended restrictions via a request.
References
Configurations
Configuration 1 (hide)
|
Information
Published : 2014-01-15 08:08
Updated : 2014-09-03 22:25
NVD link : CVE-2013-6398
Mitre link : CVE-2013-6398
JSON object : View
CWE
CWE-264
Permissions, Privileges, and Access Controls
Products Affected
apache
- cloudstack