Unrated severityNVD Advisory· Published Sep 17, 2013· Updated Jun 16, 2026
CVE-2013-2296
CVE-2013-2296
Description
Walrus in Eucalyptus before 3.2.2 does not verify authorization for the GetBucketLoggingStatus, SetBucketLoggingStatus, and SetBucketVersioningStatus bucket operations, which allows remote authenticated users to bypass intended restrictions on (1) modifying the logging setting, (2) modifying the versioning setting, or (3) accessing activity logs via a request.
Affected products
22cpe:2.3:a:eucalyptus:eucalyptus:*:*:*:*:*:*:*:*+ 21 more
- cpe:2.3:a:eucalyptus:eucalyptus:*:*:*:*:*:*:*:*range: <=3.2.1
- cpe:2.3:a:eucalyptus:eucalyptus:1.0:*:*:*:*:*:*:*
- cpe:2.3:a:eucalyptus:eucalyptus:1.1:*:*:*:*:*:*:*
- cpe:2.3:a:eucalyptus:eucalyptus:1.2:*:*:*:*:*:*:*
- cpe:2.3:a:eucalyptus:eucalyptus:1.3:*:*:*:*:*:*:*
- cpe:2.3:a:eucalyptus:eucalyptus:1.4:*:*:*:*:*:*:*
- cpe:2.3:a:eucalyptus:eucalyptus:1.5.1:*:*:*:*:*:*:*
- cpe:2.3:a:eucalyptus:eucalyptus:1.5.2:*:*:*:*:*:*:*
- cpe:2.3:a:eucalyptus:eucalyptus:1.6:*:*:*:*:*:*:*
- cpe:2.3:a:eucalyptus:eucalyptus:1.6.2:*:*:*:*:*:*:*
- cpe:2.3:a:eucalyptus:eucalyptus:2.0:*:*:*:*:*:*:*
- cpe:2.3:a:eucalyptus:eucalyptus:2.0.0:*:*:*:*:*:*:*
- cpe:2.3:a:eucalyptus:eucalyptus:2.0.1:*:*:*:*:*:*:*
- cpe:2.3:a:eucalyptus:eucalyptus:2.0.2:*:*:*:*:*:*:*
- cpe:2.3:a:eucalyptus:eucalyptus:2.0.3:*:*:*:*:*:*:*
- cpe:2.3:a:eucalyptus:eucalyptus:3.0:*:*:*:*:*:*:*
- cpe:2.3:a:eucalyptus:eucalyptus:3.0.1:*:*:*:*:*:*:*
- cpe:2.3:a:eucalyptus:eucalyptus:3.1.0:*:*:*:*:*:*:*
- cpe:2.3:a:eucalyptus:eucalyptus:3.1.1:*:*:*:*:*:*:*
- cpe:2.3:a:eucalyptus:eucalyptus:3.1.2:*:*:*:*:*:*:*
- cpe:2.3:a:eucalyptus:eucalyptus:3.2.0:*:*:*:*:*:*:*
- (no CPE)range: <3.2.2
Patches
Vulnerability mechanics
References
2- www.eucalyptus.com/resources/security/advisories/esa-10nvdVendor Advisory
- eucalyptus.atlassian.net/browse/EUCA-3074nvdVendor Advisory
News mentions
0No linked articles in our index yet.