CVE-2016-8520
Summary
| CVE | CVE-2016-8520 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-02-15 22:29:00 UTC |
| Updated | 2018-03-13 14:15:00 UTC |
| Description | HPE Helion Eucalyptus v4.3.0 and earlier does not correctly check IAM user's permissions for accessing versioned objects and ACLs. In some cases, authenticated users with S3 permissions could also access versioned data. |
Risk And Classification
Problem Types: CWE-275
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Eucalyptus | Eucalyptus | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| HP Helion Eucalyptus CVE-2016-8520 Security Bypass Vulnerability | BID | www.securityfocus.com | Third Party Advisory, VDB Entry |
| Document Display | HPE Support Center | CONFIRM | support.hpe.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.