First published: Wed Jan 04 2017(Updated: )
HPE Helion Eucalyptus v4.3.0 and earlier does not correctly check IAM user's permissions for accessing versioned objects and ACLs. In some cases, authenticated users with S3 permissions could also access versioned data.
Credit: security-alert@hpe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Eucalyptus | <=4.3.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-8520 is classified as medium severity due to its impact on access control for versioned objects.
To fix CVE-2016-8520, upgrade HPE Helion Eucalyptus to version 4.4.0 or later.
CVE-2016-8520 affects users of HPE Helion Eucalyptus version 4.3.0 and earlier.
CVE-2016-8520 allows authenticated users with S3 permissions to access versioned data without proper checks.
There is no official workaround for CVE-2016-8520; upgrading to a secure version is recommended.