CVE-2013-2296 Information

Description

Walrus in Eucalyptus before 3.2.2 does not verify authorization for the GetBucketLoggingStatus SetBucketLoggingStatus and SetBucketVersioningStatus bucket operations which allows remote authenticated users to bypass intended restrictions on (1) modifying the logging setting (2) modifying the versioning setting or (3) accessing activity logs via a request.

Reference

http://www.eucalyptus.com/resources/security/advisories/esa-10 https://eucalyptus.atlassian.net/browse/EUCA-3074

Share on: