CVE-2013-2136: XSS
Multiple cross-site scripting (XSS) vulnerabilities in Apache CloudStack before 4.1.1 allow remote attackers to inject arbitrary web script or HTML via the (1) Physical network name to the Zone wizard; (2) New network name, (3) instance name, or (4) group to the Instance wizard; (5) unspecified "multi-edit fields;" and (6) unspecified "list view" edit fields related to global settings.
Affected Software
Event History
Frequently Asked Questions
What are the security implications of CVE-2013-2136?
CVE-2013-2136 allows remote attackers to execute arbitrary web scripts or HTML on vulnerable Apache CloudStack instances due to multiple cross-site scripting (XSS) vulnerabilities.
How do I patch CVE-2013-2136?
To fix CVE-2013-2136, upgrade Apache CloudStack to version 4.1.1 or later as vulnerabilities are patched in this release.
Which versions of Apache CloudStack are affected by CVE-2013-2136?
CVE-2013-2136 affects all Apache CloudStack versions prior to 4.1.1, including the 2.x and 3.x series.
Can CVE-2013-2136 lead to data breaches?
Yes, the XSS vulnerabilities in CVE-2013-2136 may lead to unauthorized data access, which could result in data breaches.
How can I determine if my system is vulnerable to CVE-2013-2136?
You can determine if your system is vulnerable by checking the installed version of Apache CloudStack against those listed as affected in CVE-2013-2136.