CVE-2016-8520: High severity Eucalyptus Eucalyptus vulnerability
Published Feb 15, 2018
·Updated
HPE Helion Eucalyptus v4.3.0 and earlier does not correctly check IAM user's permissions for accessing versioned objects and ACLs. In some cases, authenticated users with S3 permissions could also access versioned data.
Affected Software
1 affected component
Eucalyptus Eucalyptus<=4.3.0
Event History
Feb 15, 2018
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2016-8520?
CVE-2016-8520 is classified as medium severity due to its impact on access control for versioned objects.
2
How do I fix CVE-2016-8520?
To fix CVE-2016-8520, upgrade HPE Helion Eucalyptus to version 4.4.0 or later.
3
Who is affected by CVE-2016-8520?
CVE-2016-8520 affects users of HPE Helion Eucalyptus version 4.3.0 and earlier.
4
What kind of permissions issue is present in CVE-2016-8520?
CVE-2016-8520 allows authenticated users with S3 permissions to access versioned data without proper checks.
5
Is there a workaround for CVE-2016-8520?
There is no official workaround for CVE-2016-8520; upgrading to a secure version is recommended.