Lucene search

K
cveRedhatCVE-2014-0031
HistoryJan 15, 2014 - 4:08 p.m.

CVE-2014-0031

2014-01-1516:08:04
CWE-264
redhat
web.nvd.nist.gov
27
cve-2014-0031
apache cloudstack
api
remote access
vulnerability

CVSS2

4

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:S/C:P/I:N/A:N

AI Score

6.4

Confidence

Low

EPSS

0.003

Percentile

65.5%

The (1) ListNetworkACL and (2) listNetworkACLLists APIs in Apache CloudStack before 4.2.1 allow remote authenticated users to list network ACLS for other users via a crafted request.

Affected configurations

Nvd
Node
apachecloudstackRange4.2.0
OR
apachecloudstackMatch2.0-community
OR
apachecloudstackMatch2.0.1
OR
apachecloudstackMatch2.1.0
OR
apachecloudstackMatch2.1.1
OR
apachecloudstackMatch2.1.2
OR
apachecloudstackMatch2.1.3
OR
apachecloudstackMatch2.1.4
OR
apachecloudstackMatch2.1.5
OR
apachecloudstackMatch2.1.6
OR
apachecloudstackMatch2.1.7
OR
apachecloudstackMatch2.1.8
OR
apachecloudstackMatch2.1.9
OR
apachecloudstackMatch2.1.10
OR
apachecloudstackMatch2.2.0
OR
apachecloudstackMatch2.2.1
OR
apachecloudstackMatch2.2.2
OR
apachecloudstackMatch2.2.3
OR
apachecloudstackMatch2.2.5
OR
apachecloudstackMatch2.2.6
OR
apachecloudstackMatch2.2.7
OR
apachecloudstackMatch2.2.8
OR
apachecloudstackMatch2.2.9
OR
apachecloudstackMatch2.2.11
OR
apachecloudstackMatch2.2.12
OR
apachecloudstackMatch2.2.13
OR
apachecloudstackMatch2.2.14
OR
apachecloudstackMatch3.0.0
OR
apachecloudstackMatch3.0.1
OR
apachecloudstackMatch3.0.2
OR
apachecloudstackMatch4.0.0incubating
OR
apachecloudstackMatch4.0.1
OR
apachecloudstackMatch4.0.2
OR
apachecloudstackMatch4.1.0
OR
apachecloudstackMatch4.1.1
VendorProductVersionCPE
apachecloudstack*cpe:2.3:a:apache:cloudstack:*:*:*:*:*:*:*:*
apachecloudstack2.0cpe:2.3:a:apache:cloudstack:2.0:-:community:*:*:*:*:*
apachecloudstack2.0.1cpe:2.3:a:apache:cloudstack:2.0.1:*:*:*:*:*:*:*
apachecloudstack2.1.0cpe:2.3:a:apache:cloudstack:2.1.0:*:*:*:*:*:*:*
apachecloudstack2.1.1cpe:2.3:a:apache:cloudstack:2.1.1:*:*:*:*:*:*:*
apachecloudstack2.1.2cpe:2.3:a:apache:cloudstack:2.1.2:*:*:*:*:*:*:*
apachecloudstack2.1.3cpe:2.3:a:apache:cloudstack:2.1.3:*:*:*:*:*:*:*
apachecloudstack2.1.4cpe:2.3:a:apache:cloudstack:2.1.4:*:*:*:*:*:*:*
apachecloudstack2.1.5cpe:2.3:a:apache:cloudstack:2.1.5:*:*:*:*:*:*:*
apachecloudstack2.1.6cpe:2.3:a:apache:cloudstack:2.1.6:*:*:*:*:*:*:*
Rows per page:
1-10 of 351

CVSS2

4

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:S/C:P/I:N/A:N

AI Score

6.4

Confidence

Low

EPSS

0.003

Percentile

65.5%

Related for CVE-2014-0031