漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Apache Cloudstack insecure random number generation affects project email invitation
Vulnerability Description
Apache CloudStack prior to 4.16.1.0 used insecure random number generation for project invitation tokens. If a project invite is created based only on an email address, a random token is generated. An attacker with knowledge of the project ID and the fact that the invite is sent, could generate time deterministic tokens and brute force attempt to use them prior to the legitimate receiver accepting the invite. This feature is not enabled by default, the attacker is required to know or guess the project ID for the invite in addition to the invitation token, and the attacker would need to be an existing authorized user of CloudStack.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Apache CloudStack 安全特征问题漏洞
Vulnerability Description
Apache CloudStack是美国阿帕奇(Apache)基金会的一套基础架构即服务(IaaS)云计算平台。该平台主要用于部署和管理大型虚拟机网络。 Apache CloudStack 4.16.1.0之前版本 存在安全漏洞,该漏洞源于Apache CloudStack 不安全的随机数生成影响项目电子邮件邀请。如果仅基于电子邮件地址创建项目邀请,则会生成随机令牌。该漏洞允许攻击者生成时间确定性令牌,并在合法接收者接受邀请之前暴力使用它们。默认情况下不启用此功能,除了邀请令牌之外,攻击者还需要知道或猜测
CVSS Information
N/A
Vulnerability Type
N/A