CVE-2011-0730
published 2011-06-02CVE-2011-0730: Eucalyptus before 2.0.3 and Eucalyptus EE before 2.0.2, as used in Ubuntu Enterprise Cloud (UEC) and other products, do not properly interpret signed elements…
PriorityP337medium6.5CVSS 2.0
AVNACLAuSCPIPAP
EPSS
2.17%
80.5th percentile
Eucalyptus before 2.0.3 and Eucalyptus EE before 2.0.2, as used in Ubuntu Enterprise Cloud (UEC) and other products, do not properly interpret signed elements in SOAP requests, which allows man-in-the-middle attackers to execute arbitrary commands by modifying a request, related to an "XML Signature Element Wrapping" or a "SOAP signature replay" issue.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | rampart_c | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| eucalyptus | eucalyptus | < 2.0.2 | 2.0.2 |
| eucalyptus | eucalyptus | < 2.0.3 | 2.0.3 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-xhrx-7gxr-xjcp: The rampart_timestamp_token_validate function in util/rampart_timestamp_token
ghsa_unreviewed·2022-05-17·CVSS 6.5
CVE-2011-2329 [MEDIUM] GHSA-xhrx-7gxr-xjcp: The rampart_timestamp_token_validate function in util/rampart_timestamp_token
The rampart_timestamp_token_validate function in util/rampart_timestamp_token.c in Apache Rampart/C 1.3.0 does not properly calculate the expiration of timestamp tokens, which allows remote attackers to bypass intended access restrictions by leveraging an expired token, a different vulnerability than CVE-2011-0730.
GHSA
GHSA-p2p2-m7jv-vw93: Eucalyptus before 2
ghsa_unreviewed·2022-05-14
CVE-2011-0730 [MEDIUM] CWE-20 GHSA-p2p2-m7jv-vw93: Eucalyptus before 2
Eucalyptus before 2.0.3 and Eucalyptus EE before 2.0.2, as used in Ubuntu Enterprise Cloud (UEC) and other products, do not properly interpret signed elements in SOAP requests, which allows man-in-the-middle attackers to execute arbitrary commands by modifying a request, related to an "XML Signature Element Wrapping" or a "SOAP signature replay" issue.
Ubuntu
Eucalyptus vulnerability
vendor_ubuntu·2011-05-26
CVE-2011-0730 Eucalyptus vulnerability
Title: Eucalyptus vulnerability
Summary: An attacker could send crafted input to Eucalyptus to run commands as
a valid user.
Juraj Somorovsky, Jorg Schwenk, Meiko Jensen and Xiaofeng Lou discovered
that Eucalyptus did not properly validate SOAP requests. An unauthenticated
remote attacker could exploit this to submit arbitrary commands to the
Eucalyptus SOAP interface in the context of an authenticated user.
Instructions: In general, a standard system update will make all the necessary changes.
No detection rules found.
No public exploits indexed.
http://launchpadlibrarian.net/72472626/eucalyptus_2.0.1%2Bbzr1256-0ubuntu5_2.0.1%2Bbzr1256-0ubuntu6.diff.gzhttp://open.eucalyptus.com/wiki/esa-02http://secunia.com/advisories/44705http://www.securityfocus.com/bid/48000http://www.ubuntu.com/usn/USN-1137-1https://bugs.launchpad.net/bugs/746101https://exchange.xforce.ibmcloud.com/vulnerabilities/67670https://launchpad.net/ubuntu/+source/eucalyptus/+changeloghttp://launchpadlibrarian.net/72472626/eucalyptus_2.0.1%2Bbzr1256-0ubuntu5_2.0.1%2Bbzr1256-0ubuntu6.diff.gzhttp://open.eucalyptus.com/wiki/esa-02http://secunia.com/advisories/44705http://www.securityfocus.com/bid/48000http://www.ubuntu.com/usn/USN-1137-1https://bugs.launchpad.net/bugs/746101https://exchange.xforce.ibmcloud.com/vulnerabilities/67670https://launchpad.net/ubuntu/+source/eucalyptus/+changelog
2011-06-02
Published