CVE-2013-2296
Walrus in Eucalyptus before 3.2.2 does not verify authorization for the GetBucketLoggingStatus, SetBucketLoggingStatus, and SetBucketVersioningStatus bucket operations, which allows remote authenticated users to bypass intended restrictions on (1)…
Does this matter?
Lower severity and a low EPSS score (1.01%). Track it; it rarely justifies an emergency change on its own.
Description
Walrus in Eucalyptus before 3.2.2 does not verify authorization for the GetBucketLoggingStatus, SetBucketLoggingStatus, and SetBucketVersioningStatus bucket operations, which allows remote authenticated users to bypass intended restrictions on (1) modifying the logging setting, (2) modifying the versioning setting, or (3) accessing activity logs via a request.
- CVSS 2.0
- 5.5 MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:N
- EPSS
- 1.01% probability · 61th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- eucalyptus/eucalyptus
- Source
- cve@mitre.org
References
- http://www.eucalyptus.com/resources/security/advisories/esa-10Vendor Advisory
- https://eucalyptus.atlassian.net/browse/EUCA-3074Vendor Advisory
- http://www.eucalyptus.com/resources/security/advisories/esa-10Vendor Advisory
- https://eucalyptus.atlassian.net/browse/EUCA-3074Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.