Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-p2p2-m7jv-vw93

Опубликовано: 14 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Eucalyptus before 2.0.3 and Eucalyptus EE before 2.0.2, as used in Ubuntu Enterprise Cloud (UEC) and other products, do not properly interpret signed elements in SOAP requests, which allows man-in-the-middle attackers to execute arbitrary commands by modifying a request, related to an "XML Signature Element Wrapping" or a "SOAP signature replay" issue.

Eucalyptus before 2.0.3 and Eucalyptus EE before 2.0.2, as used in Ubuntu Enterprise Cloud (UEC) and other products, do not properly interpret signed elements in SOAP requests, which allows man-in-the-middle attackers to execute arbitrary commands by modifying a request, related to an "XML Signature Element Wrapping" or a "SOAP signature replay" issue.

EPSS

Процентиль: 64%
0.00467
Низкий

Дефекты

CWE-20

Связанные уязвимости

ubuntu
больше 14 лет назад

Eucalyptus before 2.0.3 and Eucalyptus EE before 2.0.2, as used in Ubuntu Enterprise Cloud (UEC) and other products, do not properly interpret signed elements in SOAP requests, which allows man-in-the-middle attackers to execute arbitrary commands by modifying a request, related to an "XML Signature Element Wrapping" or a "SOAP signature replay" issue.

nvd
больше 14 лет назад

Eucalyptus before 2.0.3 and Eucalyptus EE before 2.0.2, as used in Ubuntu Enterprise Cloud (UEC) and other products, do not properly interpret signed elements in SOAP requests, which allows man-in-the-middle attackers to execute arbitrary commands by modifying a request, related to an "XML Signature Element Wrapping" or a "SOAP signature replay" issue.

debian
больше 14 лет назад

Eucalyptus before 2.0.3 and Eucalyptus EE before 2.0.2, as used in Ubu ...

EPSS

Процентиль: 64%
0.00467
Низкий

Дефекты

CWE-20