CVE-2013-0267 Information
Description
The Privileges portion of the web GUI and the XMLRPC API in Apache VCL 2.3.x before 2.3.2 2.2.x before 2.2.2 and 2.1 allow remote authenticated users with nodeAdmin manageGroup resourceGrant or userGrant permissions to gain privileges cause a denial of service or conduct cross-site scripting (XSS) attacks by leveraging improper data validation.
CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Reference
https://github.com/apache/vcl/commit/56c0f040056d6ad8693b20cfd3351367c2ffeabcdiff-2567a5ec9705eb7ac2c984033e06189d https://lists.apache.org/thread.html/632da9e45fce333f21782f1fe10b1d8e77a63811a34fe8e286dedc99@3Ccommits.vcl.apache.org3E https://lists.apache.org/thread.html/944592973c91cd106a42095271c3f6c7ab9c8d70077b8c6a8d4d92d0@3Ccommits.vcl.apache.org3E https://mail-archives.apache.org/mod_mbox/www-announce/201305.mbox/3C1658214.8zndv4WEi7@treebeard3E
Attack Complexity
LOW
Privileges Required
LOW
User Interaction Required
LOW
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
HIGH
Base Score
HIGH
Base Severity
8.8
Share on: