5
CVE-2012-4066
- EPSS 0.2%
- Veröffentlicht 08.03.2013 18:55:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
The internal message protocol for Walrus in Eucalyptus 3.2.0 and earlier does not require signatures for unspecified request headers, which allows attackers to (1) delete or (2) upload snapshots.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Eucalyptus ≫ Eucalyptus Version <= 3.2.0
Eucalyptus ≫ Eucalyptus Version1.0
Eucalyptus ≫ Eucalyptus Version1.1
Eucalyptus ≫ Eucalyptus Version1.2
Eucalyptus ≫ Eucalyptus Version1.3
Eucalyptus ≫ Eucalyptus Version1.4
Eucalyptus ≫ Eucalyptus Version1.5.1
Eucalyptus ≫ Eucalyptus Version1.5.2
Eucalyptus ≫ Eucalyptus Version1.6
Eucalyptus ≫ Eucalyptus Version1.6.2
Eucalyptus ≫ Eucalyptus Version2.0
Eucalyptus ≫ Eucalyptus Version2.0.0
Eucalyptus ≫ Eucalyptus Version2.0.1
Eucalyptus ≫ Eucalyptus Version2.0.2
Eucalyptus ≫ Eucalyptus Version2.0.3
Eucalyptus ≫ Eucalyptus Version3.0
Eucalyptus ≫ Eucalyptus Version3.0.1
Eucalyptus ≫ Eucalyptus Version3.1.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.2% | 0.386 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:N/I:P/A:N
|
CWE-287 Improper Authentication
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.