Show filters
3 Total Results
Displaying 1-3 of 3
Sort by:
Attacker Value
Unknown

CVE-2013-4317

Disclosure Date: February 06, 2018 (last updated November 26, 2024)
In Apache CloudStack 4.1.0 and 4.1.1, when calling the CloudStack API call listProjectAccounts as a regular, non-administrative user, the user is able to see information for accounts other than their own.
0
Attacker Value
Unknown

CVE-2013-6398

Disclosure Date: January 15, 2014 (last updated October 05, 2023)
The virtual router in Apache CloudStack before 4.2.1 does not preserve the source restrictions in firewall rules after being restarted, which allows remote attackers to bypass intended restrictions via a request.
0
Attacker Value
Unknown

CVE-2014-0031

Disclosure Date: January 15, 2014 (last updated October 05, 2023)
The (1) ListNetworkACL and (2) listNetworkACLLists APIs in Apache CloudStack before 4.2.1 allow remote authenticated users to list network ACLS for other users via a crafted request.
0