CVE-2013-2296
Summary
| CVE | CVE-2013-2296 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2013-09-17 12:04:16 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | Walrus in Eucalyptus before 3.2.2 does not verify authorization for the GetBucketLoggingStatus, SetBucketLoggingStatus, and SetBucketVersioningStatus bucket operations, which allows remote authenticated users to bypass intended restrictions on (1) modifying the logging setting, (2) modifying the versioning setting, or (3) accessing activity logs via a request. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
SingleConfidentiality
PartialIntegrity
PartialAvailability
NoneAV:N/AC:L/Au:S/C:P/I:P/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Eucalyptus | Eucalyptus | 1.0 | All | All | All |
| Application | Eucalyptus | Eucalyptus | 1.1 | All | All | All |
| Application | Eucalyptus | Eucalyptus | 1.2 | All | All | All |
| Application | Eucalyptus | Eucalyptus | 1.3 | All | All | All |
| Application | Eucalyptus | Eucalyptus | 1.4 | All | All | All |
| Application | Eucalyptus | Eucalyptus | 1.5.1 | All | All | All |
| Application | Eucalyptus | Eucalyptus | 1.5.2 | All | All | All |
| Application | Eucalyptus | Eucalyptus | 1.6 | All | All | All |
| Application | Eucalyptus | Eucalyptus | 1.6.2 | All | All | All |
| Application | Eucalyptus | Eucalyptus | 2.0 | All | All | All |
| Application | Eucalyptus | Eucalyptus | 2.0.0 | All | All | All |
| Application | Eucalyptus | Eucalyptus | 2.0.1 | All | All | All |
| Application | Eucalyptus | Eucalyptus | 2.0.2 | All | All | All |
| Application | Eucalyptus | Eucalyptus | 2.0.3 | All | All | All |
| Application | Eucalyptus | Eucalyptus | 3.0 | All | All | All |
| Application | Eucalyptus | Eucalyptus | 3.0.1 | All | All | All |
| Application | Eucalyptus | Eucalyptus | 3.1.0 | All | All | All |
| Application | Eucalyptus | Eucalyptus | 3.1.1 | All | All | All |
| Application | Eucalyptus | Eucalyptus | 3.1.2 | All | All | All |
| Application | Eucalyptus | Eucalyptus | 3.2.0 | All | All | All |
| Application | Eucalyptus | Eucalyptus | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| ESA-10: Missing Authorization Vulnerability in Walrus | Eucalyptus | af854a3a-2127-422b-91ae-364da2661108 | www.eucalyptus.com | Vendor Advisory |
| Log in with Atlassian account | af854a3a-2127-422b-91ae-364da2661108 | eucalyptus.atlassian.net | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.