Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Eucalyptus before 3.1.1 does not properly restrict the binding of external SOAP web-services messages, which allows remote authenticated users to bypass unspecified authorization checks and obtain direct access to a (1) Cloud Controller or (2) Walrus service via a crafted message, as demonstrated by changes to a volume, snapshot, or cloud configuration setting.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Eucalyptus 安全绕过漏洞
Vulnerability Description
Eucalyptus是美国加利福尼亚大学Santa Barbara计算机科学院的一个研究项目,它是一个用于实现云计算的开源软件基础设施,也是Amazon EC2(亚马逊弹性计算云)的一个开源实现。 Eucalyptus中存在漏洞,可被恶意用户利用绕过某些安全限制并导致DoS(拒绝服务)。该漏洞源于访问某些服务时,Cloud Controller和Walrus SOAP web服务器组件授权机制未正确验证凭证。可被利用如控制其他用户的网络分卷和快照。早期版本至3.1.1版本中存在漏洞。
CVSS Information
N/A
Vulnerability Type
N/A