CVE-2013-4766 – org.jclouds.api:eucalyptus
Package
Manager: maven
Name: org.jclouds.api:eucalyptus
Vulnerable Version: >=0 <3.3.1
Severity
Level: Medium
CVSS v3.1: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
EPSS: 0.0025 pctl0.48226
Details
Eucalyptus Unauthorized Access to CC/NC Log Files The gather log service in Eucalyptus before 3.3.1 allows remote attackers to read log files via an unspecified request to the (1) Cluster Controller (CC) or (2) Node Controller (NC) component.
Metadata
Created: 2022-05-17T05:04:27Z
Modified: 2023-08-29T18:57:27Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-f5hm-h272-2qwm/GHSA-f5hm-h272-2qwm.json
CWE IDs: ["CWE-200"]
Alternative ID: GHSA-f5hm-h272-2qwm
Finding: F310
Auto approve: 1