Show filters
3 Total Results
Displaying 1-3 of 3
Sort by:
Attacker Value
Unknown
CVE-2013-4317
Disclosure Date: February 06, 2018 (last updated November 26, 2024)
In Apache CloudStack 4.1.0 and 4.1.1, when calling the CloudStack API call listProjectAccounts as a regular, non-administrative user, the user is able to see information for accounts other than their own.
0
Attacker Value
Unknown
CVE-2013-6398
Disclosure Date: January 15, 2014 (last updated October 05, 2023)
The virtual router in Apache CloudStack before 4.2.1 does not preserve the source restrictions in firewall rules after being restarted, which allows remote attackers to bypass intended restrictions via a request.
0
Attacker Value
Unknown
CVE-2014-0031
Disclosure Date: January 15, 2014 (last updated October 05, 2023)
The (1) ListNetworkACL and (2) listNetworkACLLists APIs in Apache CloudStack before 4.2.1 allow remote authenticated users to list network ACLS for other users via a crafted request.
0