Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Walrus in Eucalyptus before 3.2.2 does not verify authorization for the GetBucketLoggingStatus, SetBucketLoggingStatus, and SetBucketVersioningStatus bucket operations, which allows remote authenticated users to bypass intended restrictions on (1) modifying the logging setting, (2) modifying the versioning setting, or (3) accessing activity logs via a request.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Eucalyptus Walrus 安全绕过漏洞
Vulnerability Description
Eucalyptus是美国加利福尼亚大学Santa Barbara计算机科学院的一个研究项目,它是一个用于实现云计算的开源软件基础设施,也是Amazon EC2(亚马逊弹性计算云)的一个开源实现。 Eucalyptus 3.2.2之前版本中的Walrus组件中存在安全绕过漏洞,该漏洞源于程序没有对GetBucketLoggingStatus,SetBucketLoggingStatus和SetBucketVersioningStatus等操作进行授权验证。远程认证攻击者可通过发送特制请求利用该漏洞绕过位于
CVSS Information
N/A
Vulnerability Type
N/A