Proxmox VE 'AccessControl.pm' User Enumeration Vulnerability
BID:68028
CVE-2014-4156 |Info
Proxmox VE 'AccessControl.pm' User Enumeration Vulnerability
| Bugtraq ID: | 68028 |
| Class: | Design Error |
| CVE: |
CVE-2014-4156 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 18 2013 12:00AM |
| Updated: | Jun 18 2014 06:34AM |
| Credit: | Damien Cauquil of Sysdream |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
Proxmox VE 'AccessControl.pm' User Enumeration Vulnerability
Proxmox VE is prone to a user-enumeration vulnerability.
An attacker may leverage this issue to harvest valid usernames, which may aid in further attacks.
Versions prior to Proxmox VE 3.2 are vulnerable.
Proxmox VE is prone to a user-enumeration vulnerability.
An attacker may leverage this issue to harvest valid usernames, which may aid in further attacks.
Versions prior to Proxmox VE 3.2 are vulnerable.
Exploit / POC
Proxmox VE 'AccessControl.pm' User Enumeration Vulnerability
An attacker can exploit this issue by supplying the application with crafted requests.
An attacker can exploit this issue by supplying the application with crafted requests.
Solution / Fix
Proxmox VE 'AccessControl.pm' User Enumeration Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Proxmox VE 'AccessControl.pm' User Enumeration Vulnerability
References:
References: