CVE-2013-2296: Medium severity eucalyptus vulnerability
Walrus in Eucalyptus before 3.2.2 does not verify authorization for the GetBucketLoggingStatus, SetBucketLoggingStatus, and SetBucketVersioningStatus bucket operations, which allows remote authenticated users to bypass intended restrictions on (1) modifying the logging setting, (2) modifying the versioning setting, or (3) accessing activity logs via a request.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-2296?
CVE-2013-2296 is classified as a medium severity vulnerability due to improper authorization handling in bucket operations.
How do I fix CVE-2013-2296?
To fix CVE-2013-2296, upgrade to Eucalyptus version 3.2.2 or newer.
Which versions of Eucalyptus are affected by CVE-2013-2296?
CVE-2013-2296 affects all Eucalyptus versions prior to 3.2.2, as well as specific older versions up to 1.6.2.
What attacks are possible due to CVE-2013-2296?
Due to CVE-2013-2296, remote authenticated users can bypass permissions to modify bucket logging and versioning settings.
Is user authentication sufficient to protect against CVE-2013-2296?
No, user authentication is not sufficient as CVE-2013-2296 allows authenticated users to bypass intended access restrictions.