First published: Mon Aug 19 2013(Updated: )
Multiple cross-site scripting (XSS) vulnerabilities in Apache CloudStack before 4.1.1 allow remote attackers to inject arbitrary web script or HTML via the (1) Physical network name to the Zone wizard; (2) New network name, (3) instance name, or (4) group to the Instance wizard; (5) unspecified "multi-edit fields;" and (6) unspecified "list view" edit fields related to global settings.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apache CloudStack | <=4.1.0 | |
Apache CloudStack | =2.0 | |
Apache CloudStack | =2.0.1 | |
Apache CloudStack | =2.1.0 | |
Apache CloudStack | =2.1.1 | |
Apache CloudStack | =2.1.2 | |
Apache CloudStack | =2.1.3 | |
Apache CloudStack | =2.1.4 | |
Apache CloudStack | =2.1.5 | |
Apache CloudStack | =2.1.6 | |
Apache CloudStack | =2.1.7 | |
Apache CloudStack | =2.1.8 | |
Apache CloudStack | =2.1.9 | |
Apache CloudStack | =2.1.10 | |
Apache CloudStack | =2.2.0 | |
Apache CloudStack | =2.2.1 | |
Apache CloudStack | =2.2.2 | |
Apache CloudStack | =2.2.3 | |
Apache CloudStack | =2.2.5 | |
Apache CloudStack | =2.2.6 | |
Apache CloudStack | =2.2.7 | |
Apache CloudStack | =2.2.8 | |
Apache CloudStack | =2.2.9 | |
Apache CloudStack | =2.2.11 | |
Apache CloudStack | =2.2.12 | |
Apache CloudStack | =2.2.13 | |
Apache CloudStack | =2.2.14 | |
Apache CloudStack | =3.0.0 | |
Apache CloudStack | =3.0.1 | |
Apache CloudStack | =3.0.2 | |
Apache CloudStack | =4.0.0-incubating | |
Apache CloudStack | =4.0.1 | |
Apache CloudStack | =4.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-2136 allows remote attackers to execute arbitrary web scripts or HTML on vulnerable Apache CloudStack instances due to multiple cross-site scripting (XSS) vulnerabilities.
To fix CVE-2013-2136, upgrade Apache CloudStack to version 4.1.1 or later as vulnerabilities are patched in this release.
CVE-2013-2136 affects all Apache CloudStack versions prior to 4.1.1, including the 2.x and 3.x series.
Yes, the XSS vulnerabilities in CVE-2013-2136 may lead to unauthorized data access, which could result in data breaches.
You can determine if your system is vulnerable by checking the installed version of Apache CloudStack against those listed as affected in CVE-2013-2136.