CVE-2013-2756: Medium severity Apache CloudStack vulnerability
Apache CloudStack 4.0.0 before 4.0.2 and Citrix CloudPlatform (formerly Citrix CloudStack) 3.0.x before 3.0.6 Patch C allows remote attackers to bypass the console proxy authentication by leveraging knowledge of the source code.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2013-2756?
CVE-2013-2756 is considered a medium severity vulnerability due to its potential for unauthorized access.
How do I fix CVE-2013-2756?
To fix CVE-2013-2756, upgrade to Apache CloudStack version 4.0.2 or Citrix CloudPlatform version 3.0.6 or later.
Which versions are affected by CVE-2013-2756?
CVE-2013-2756 affects Apache CloudStack versions 4.0.0 and 4.0.1 and Citrix CloudPlatform versions prior to 3.0.6.
What are the ways an attacker can exploit CVE-2013-2756?
An attacker can exploit CVE-2013-2756 by bypassing the console proxy authentication using knowledge of the source code.
Is there a workaround for CVE-2013-2756?
There are no known workarounds for CVE-2013-2756; patching the software is the recommended action.