Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Eucalyptus before 3.1.1 does not properly restrict the binding of external SOAP web-services messages, which allows remote authenticated users to gain privileges by sending a message to (1) Cloud Controller or (2) Walrus with the internal message format and a modified user id.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Eucalyptus 权限获取漏洞
Vulnerability Description
Eucalyptus是美国加利福尼亚大学Santa Barbara计算机科学院的一个研究项目,它是一个用于实现云计算的开源软件基础设施,也是Amazon EC2(亚马逊弹性计算云)的一个开源实现。 Eucalyptus中存在漏洞,可被恶意用户利用绕过某些安全限制并导致DoS(拒绝服务)。该漏洞源于在内部格式中提交消息时,Cloud Controller和Walrus SOAP web服务器组件未正确验证凭证,可被利用获取管理权限。早期版本至3.1.1版本中存在漏洞。
CVSS Information
N/A
Vulnerability Type
N/A