CVE-2011-0730: Input Validation
Eucalyptus before 2.0.3 and Eucalyptus EE before 2.0.2, as used in Ubuntu Enterprise Cloud (UEC) and other products, do not properly interpret signed elements in SOAP requests, which allows man-in-the-middle attackers to execute arbitrary commands by modifying a request, related to an "XML Signature Element Wrapping" or a "SOAP signature replay" issue.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2011-0730?
CVE-2011-0730 is classified as a high severity vulnerability due to its potential for man-in-the-middle attacks.
How do I fix CVE-2011-0730?
To fix CVE-2011-0730, upgrade Eucalyptus to version 2.0.3 or later and ensure that you are using updated versions of Ubuntu 10.10, 11.04, or 10.04 LTS.
What products are affected by CVE-2011-0730?
CVE-2011-0730 affects Eucalyptus versions before 2.0.3 and Eucalyptus EE versions before 2.0.2, along with specific Ubuntu releases.
What type of attack does CVE-2011-0730 enable?
CVE-2011-0730 enables man-in-the-middle attacks that can result in arbitrary command execution by modifying SOAP request elements.
Is there a workaround for CVE-2011-0730 if I cannot upgrade?
There are no effective workarounds for CVE-2011-0730, and upgrading is strongly recommended.