4

CVE-2014-0031

The (1) ListNetworkACL and (2) listNetworkACLLists APIs in Apache CloudStack before 4.2.1 allow remote authenticated users to list network ACLS for other users via a crafted request.

Data is provided by the National Vulnerability Database (NVD)
ApacheCloudstack Version <= 4.2.0
ApacheCloudstack Version2.0 Update- Editioncommunity
ApacheCloudstack Version2.0.1
ApacheCloudstack Version2.1.0
ApacheCloudstack Version2.1.1
ApacheCloudstack Version2.1.2
ApacheCloudstack Version2.1.3
ApacheCloudstack Version2.1.4
ApacheCloudstack Version2.1.5
ApacheCloudstack Version2.1.6
ApacheCloudstack Version2.1.7
ApacheCloudstack Version2.1.8
ApacheCloudstack Version2.1.9
ApacheCloudstack Version2.1.10
ApacheCloudstack Version2.2.0
ApacheCloudstack Version2.2.1
ApacheCloudstack Version2.2.2
ApacheCloudstack Version2.2.3
ApacheCloudstack Version2.2.5
ApacheCloudstack Version2.2.6
ApacheCloudstack Version2.2.7
ApacheCloudstack Version2.2.8
ApacheCloudstack Version2.2.9
ApacheCloudstack Version2.2.11
ApacheCloudstack Version2.2.12
ApacheCloudstack Version2.2.13
ApacheCloudstack Version2.2.14
ApacheCloudstack Version3.0.0
ApacheCloudstack Version3.0.1
ApacheCloudstack Version3.0.2
ApacheCloudstack Version4.0.0 Updateincubating
ApacheCloudstack Version4.0.1
ApacheCloudstack Version4.0.2
ApacheCloudstack Version4.1.0
ApacheCloudstack Version4.1.1
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.32% 0.523
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 4 8 2.9
AV:N/AC:L/Au:S/C:P/I:N/A:N