First published: Fri Oct 26 2012(Updated: )
Citrix Cloud.com CloudStack, and Apache CloudStack pre-release, allows remote attackers to make arbitrary API calls by leveraging the system user account, as demonstrated by API calls to delete VMs.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apache CloudStack | =prerelease | |
Citrix |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-4501 is considered a high severity vulnerability due to the potential for remote attackers to execute arbitrary API calls.
To fix CVE-2012-4501, ensure that you update to the latest stable version of Citrix CloudStack or Apache CloudStack that addresses this vulnerability.
CVE-2012-4501 affects Citrix CloudStack and pre-release versions of Apache CloudStack.
CVE-2012-4501 allows remote attackers to execute arbitrary API commands, including the deletion of virtual machines.
While the best solution is to upgrade, administrators can limit access to the affected APIs as a temporary workaround for CVE-2012-4501.