Bug 952858 (CVE-2013-2296) - CVE-2013-2296 eucalyptus: Missing Authorization Vulnerability in Walrus
Summary: CVE-2013-2296 eucalyptus: Missing Authorization Vulnerability in Walrus
Keywords:
Status: CLOSED NOTABUG
Alias: CVE-2013-2296
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: Unspecified
OS: Unspecified
low
low
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 953355
Blocks:
TreeView+ depends on / blocked
 
Reported: 2013-04-16 21:24 UTC by Andy Grimm
Modified: 2021-02-17 07:49 UTC (History)
2 users (show)

Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Clone Of:
Environment:
Last Closed: 2013-04-18 02:49:53 UTC
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Eucalyptus JIRA EUCA-3074 0 None None None Never

Description Andy Grimm 2013-04-16 21:24:59 UTC
A flaw was
identified in the way Walrus checks authorization for some operations
on buckets. As a result, an authenticated user does not require
authorization to enable logging and versioning on buckets and
could potentially get access to activity logs for that bucket.

Links:
http://www.eucalyptus.com/eucalyptus-cloud/security/esa-10
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2296
https://eucalyptus.atlassian.net/browse/EUCA-3074

Comment 1 David Jorm 2013-04-18 02:48:26 UTC
Statement:

Not affected. This flaw does not affect the jclouds Eucalyptus API as shipped with JBoss Fuse 6.0.0 and Fuse ESB Enterprise 7.1.0.

Comment 2 David Jorm 2013-04-18 02:49:09 UTC
Created eucalyptus tracking bugs for this issue

Affects: fedora-all [bug 953355]


Note You need to log in before you can comment on or make changes to this bug.