Логотип exploitDog
bind:CVE-2016-6813
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2016-6813

Количество 2

Количество 2

nvd логотип

CVE-2016-6813

около 8 лет назад

Apache CloudStack 4.1 to 4.8.1.0 and 4.9.0.0 contain an API call designed to allow a user to register for the developer API. If a malicious user is able to determine the ID of another (non-"root") CloudStack user, the malicious user may be able to reset the API keys for the other user, in turn accessing their account and resources.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-hrqr-xjpc-vfrf

больше 3 лет назад

Apache CloudStack 4.1 to 4.8.1.0 and 4.9.0.0 contain an API call designed to allow a user to register for the developer API. If a malicious user is able to determine the ID of another (non-"root") CloudStack user, the malicious user may be able to reset the API keys for the other user, in turn accessing their account and resources.

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2016-6813

Apache CloudStack 4.1 to 4.8.1.0 and 4.9.0.0 contain an API call designed to allow a user to register for the developer API. If a malicious user is able to determine the ID of another (non-"root") CloudStack user, the malicious user may be able to reset the API keys for the other user, in turn accessing their account and resources.

CVSS3: 9.8
2%
Низкий
около 8 лет назад
github логотип
GHSA-hrqr-xjpc-vfrf

Apache CloudStack 4.1 to 4.8.1.0 and 4.9.0.0 contain an API call designed to allow a user to register for the developer API. If a malicious user is able to determine the ID of another (non-"root") CloudStack user, the malicious user may be able to reset the API keys for the other user, in turn accessing their account and resources.

CVSS3: 9.8
2%
Низкий
больше 3 лет назад

Уязвимостей на страницу