First published: Fri Oct 26 2012(Updated: )
Citrix Cloud.com CloudStack, and Apache CloudStack pre-release, allows remote attackers to make arbitrary API calls by leveraging the system user account, as demonstrated by API calls to delete VMs.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apache CloudStack | =prerelease | |
Citrix Cloudstack |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.