CVE-2013-2296
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Walrus in Eucalyptus before 3.2.2 does not verify authorization for the GetBucketLoggingStatus, SetBucketLoggingStatus, and SetBucketVersioningStatus bucket operations, which allows remote authenticated users to bypass intended restrictions on (1) modifying the logging setting, (2) modifying the versioning setting, or (3) accessing activity logs via a request.
Walrus en Eucalyptus anteriores a v3.2.2 no verifica la autorización para las operaciones GetBucketLoggingStatus, setBucketLoggingStatus, y SetBucketVersioningStatus, lo cual permite a usuarios autenticados evitar restricciones establecidas (1) modificando la configuración de registro, (2) modificando la configuración de versionado, o (3) accediendo a los logs de actividad a través de una petición.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2013-03-02 CVE Reserved
- 2013-09-17 CVE Published
- 2024-09-17 CVE Updated
- 2024-09-17 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-264: Permissions, Privileges, and Access Controls
CAPEC
References (2)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://www.eucalyptus.com/resources/security/advisories/esa-10 | 2013-09-18 | |
https://eucalyptus.atlassian.net/browse/EUCA-3074 | 2013-09-18 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Eucalyptus Search vendor "Eucalyptus" | Eucalyptus Search vendor "Eucalyptus" for product "Eucalyptus" | <= 3.2.1 Search vendor "Eucalyptus" for product "Eucalyptus" and version " <= 3.2.1" | - |
Affected
| ||||||
Eucalyptus Search vendor "Eucalyptus" | Eucalyptus Search vendor "Eucalyptus" for product "Eucalyptus" | 1.0 Search vendor "Eucalyptus" for product "Eucalyptus" and version "1.0" | - |
Affected
| ||||||
Eucalyptus Search vendor "Eucalyptus" | Eucalyptus Search vendor "Eucalyptus" for product "Eucalyptus" | 1.1 Search vendor "Eucalyptus" for product "Eucalyptus" and version "1.1" | - |
Affected
| ||||||
Eucalyptus Search vendor "Eucalyptus" | Eucalyptus Search vendor "Eucalyptus" for product "Eucalyptus" | 1.2 Search vendor "Eucalyptus" for product "Eucalyptus" and version "1.2" | - |
Affected
| ||||||
Eucalyptus Search vendor "Eucalyptus" | Eucalyptus Search vendor "Eucalyptus" for product "Eucalyptus" | 1.3 Search vendor "Eucalyptus" for product "Eucalyptus" and version "1.3" | - |
Affected
| ||||||
Eucalyptus Search vendor "Eucalyptus" | Eucalyptus Search vendor "Eucalyptus" for product "Eucalyptus" | 1.4 Search vendor "Eucalyptus" for product "Eucalyptus" and version "1.4" | - |
Affected
| ||||||
Eucalyptus Search vendor "Eucalyptus" | Eucalyptus Search vendor "Eucalyptus" for product "Eucalyptus" | 1.5.1 Search vendor "Eucalyptus" for product "Eucalyptus" and version "1.5.1" | - |
Affected
| ||||||
Eucalyptus Search vendor "Eucalyptus" | Eucalyptus Search vendor "Eucalyptus" for product "Eucalyptus" | 1.5.2 Search vendor "Eucalyptus" for product "Eucalyptus" and version "1.5.2" | - |
Affected
| ||||||
Eucalyptus Search vendor "Eucalyptus" | Eucalyptus Search vendor "Eucalyptus" for product "Eucalyptus" | 1.6 Search vendor "Eucalyptus" for product "Eucalyptus" and version "1.6" | - |
Affected
| ||||||
Eucalyptus Search vendor "Eucalyptus" | Eucalyptus Search vendor "Eucalyptus" for product "Eucalyptus" | 1.6.2 Search vendor "Eucalyptus" for product "Eucalyptus" and version "1.6.2" | - |
Affected
| ||||||
Eucalyptus Search vendor "Eucalyptus" | Eucalyptus Search vendor "Eucalyptus" for product "Eucalyptus" | 2.0 Search vendor "Eucalyptus" for product "Eucalyptus" and version "2.0" | - |
Affected
| ||||||
Eucalyptus Search vendor "Eucalyptus" | Eucalyptus Search vendor "Eucalyptus" for product "Eucalyptus" | 2.0.0 Search vendor "Eucalyptus" for product "Eucalyptus" and version "2.0.0" | - |
Affected
| ||||||
Eucalyptus Search vendor "Eucalyptus" | Eucalyptus Search vendor "Eucalyptus" for product "Eucalyptus" | 2.0.1 Search vendor "Eucalyptus" for product "Eucalyptus" and version "2.0.1" | - |
Affected
| ||||||
Eucalyptus Search vendor "Eucalyptus" | Eucalyptus Search vendor "Eucalyptus" for product "Eucalyptus" | 2.0.2 Search vendor "Eucalyptus" for product "Eucalyptus" and version "2.0.2" | - |
Affected
| ||||||
Eucalyptus Search vendor "Eucalyptus" | Eucalyptus Search vendor "Eucalyptus" for product "Eucalyptus" | 2.0.3 Search vendor "Eucalyptus" for product "Eucalyptus" and version "2.0.3" | - |
Affected
| ||||||
Eucalyptus Search vendor "Eucalyptus" | Eucalyptus Search vendor "Eucalyptus" for product "Eucalyptus" | 3.0 Search vendor "Eucalyptus" for product "Eucalyptus" and version "3.0" | - |
Affected
| ||||||
Eucalyptus Search vendor "Eucalyptus" | Eucalyptus Search vendor "Eucalyptus" for product "Eucalyptus" | 3.0.1 Search vendor "Eucalyptus" for product "Eucalyptus" and version "3.0.1" | - |
Affected
| ||||||
Eucalyptus Search vendor "Eucalyptus" | Eucalyptus Search vendor "Eucalyptus" for product "Eucalyptus" | 3.1.0 Search vendor "Eucalyptus" for product "Eucalyptus" and version "3.1.0" | - |
Affected
| ||||||
Eucalyptus Search vendor "Eucalyptus" | Eucalyptus Search vendor "Eucalyptus" for product "Eucalyptus" | 3.1.1 Search vendor "Eucalyptus" for product "Eucalyptus" and version "3.1.1" | - |
Affected
| ||||||
Eucalyptus Search vendor "Eucalyptus" | Eucalyptus Search vendor "Eucalyptus" for product "Eucalyptus" | 3.1.2 Search vendor "Eucalyptus" for product "Eucalyptus" and version "3.1.2" | - |
Affected
| ||||||
Eucalyptus Search vendor "Eucalyptus" | Eucalyptus Search vendor "Eucalyptus" for product "Eucalyptus" | 3.2.0 Search vendor "Eucalyptus" for product "Eucalyptus" and version "3.2.0" | - |
Affected
|