First published: Mon Oct 01 2012(Updated: )
Eucalyptus before 3.1.1 does not properly restrict the binding of external SOAP web-services messages, which allows remote authenticated users to gain privileges by sending a message to (1) Cloud Controller or (2) Walrus with the internal message format and a modified user id.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Eucalyptus | <=3.1.0 | |
Eucalyptus | =1.0 | |
Eucalyptus | =1.1 | |
Eucalyptus | =1.2 | |
Eucalyptus | =1.3 | |
Eucalyptus | =1.4 | |
Eucalyptus | =1.5.1 | |
Eucalyptus | =1.5.2 | |
Eucalyptus | =1.6 | |
Eucalyptus | =1.6.2 | |
Eucalyptus | =2.0 | |
Eucalyptus | =2.0.0 | |
Eucalyptus | =2.0.1 | |
Eucalyptus | =2.0.2 | |
Eucalyptus | =2.0.3 | |
Eucalyptus | =3.0 | |
Eucalyptus | =3.0.1 | |
Eucalyptus | =3.1.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-4064 has a medium severity rating due to potential privilege escalation risks.
To mitigate CVE-2012-4064, upgrade Eucalyptus to version 3.1.1 or later.
CVE-2012-4064 affects Eucalyptus versions up to 3.1.0, along with several 1.x and 2.x versions.
Remote authenticated users can be potentially affected by CVE-2012-4064 through unauthorized privilege escalation.
CVE-2012-4064 involves improper restrictions on external SOAP web-services messages, leading to privilege escalation.