Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2011-0730

Опубликовано: 02 июн. 2011
Источник: nvd
CVSS2: 6.5
EPSS Низкий

Описание

Eucalyptus before 2.0.3 and Eucalyptus EE before 2.0.2, as used in Ubuntu Enterprise Cloud (UEC) and other products, do not properly interpret signed elements in SOAP requests, which allows man-in-the-middle attackers to execute arbitrary commands by modifying a request, related to an "XML Signature Element Wrapping" or a "SOAP signature replay" issue.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:eucalyptus:eucalyptus:*:*:*:*:enterprise:*:*:*
Версия до 2.0.2 (исключая)
cpe:2.3:a:eucalyptus:eucalyptus:*:*:*:*:*:*:*:*
Версия до 2.0.3 (исключая)
Конфигурация 2

Одно из

cpe:2.3:o:canonical:ubuntu_linux:10.04:*:*:*:lts:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:10.10:*:*:*:*:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:11.04:*:*:*:*:*:*:*

EPSS

Процентиль: 64%
0.00467
Низкий

6.5 Medium

CVSS2

Дефекты

CWE-20

Связанные уязвимости

ubuntu
больше 14 лет назад

Eucalyptus before 2.0.3 and Eucalyptus EE before 2.0.2, as used in Ubuntu Enterprise Cloud (UEC) and other products, do not properly interpret signed elements in SOAP requests, which allows man-in-the-middle attackers to execute arbitrary commands by modifying a request, related to an "XML Signature Element Wrapping" or a "SOAP signature replay" issue.

debian
больше 14 лет назад

Eucalyptus before 2.0.3 and Eucalyptus EE before 2.0.2, as used in Ubu ...

github
больше 3 лет назад

Eucalyptus before 2.0.3 and Eucalyptus EE before 2.0.2, as used in Ubuntu Enterprise Cloud (UEC) and other products, do not properly interpret signed elements in SOAP requests, which allows man-in-the-middle attackers to execute arbitrary commands by modifying a request, related to an "XML Signature Element Wrapping" or a "SOAP signature replay" issue.

EPSS

Процентиль: 64%
0.00467
Низкий

6.5 Medium

CVSS2

Дефекты

CWE-20