356
VMScore

CVE-2013-4317

Published: 06/02/2018 Updated: 26/02/2018
CVSS v2 Base Score: 4 | Impact Score: 2.9 | Exploitability Score: 8
CVSS v3 Base Score: 4.3 | Impact Score: 1.4 | Exploitability Score: 2.8
VMScore: 356
Vector: AV:N/AC:L/Au:S/C:P/I:N/A:N

Vulnerability Summary

In Apache CloudStack 4.1.0 and 4.1.1, when calling the CloudStack API call listProjectAccounts as a regular, non-administrative user, the user is able to see information for accounts other than their own.

Vulnerable Product Search on Vulmon Subscribe to Product

apache cloudstack 4.1.0

apache cloudstack 4.1.1

Vendor Advisories

In Apache CloudStack 410 and 411, when calling the CloudStack API call listProjectAccounts as a regular, non-administrative user, the user is able to see information for accounts other than their own ...