Unrated severityNVD Advisory· Published Sep 17, 2013· Updated Apr 29, 2026
CVE-2013-2296
CVE-2013-2296
Description
Walrus in Eucalyptus before 3.2.2 does not verify authorization for the GetBucketLoggingStatus, SetBucketLoggingStatus, and SetBucketVersioningStatus bucket operations, which allows remote authenticated users to bypass intended restrictions on (1) modifying the logging setting, (2) modifying the versioning setting, or (3) accessing activity logs via a request.
Affected products
21cpe:2.3:a:eucalyptus:eucalyptus:*:*:*:*:*:*:*:*+ 20 more
- cpe:2.3:a:eucalyptus:eucalyptus:*:*:*:*:*:*:*:*range: <=3.2.1
- cpe:2.3:a:eucalyptus:eucalyptus:1.0:*:*:*:*:*:*:*
- cpe:2.3:a:eucalyptus:eucalyptus:1.1:*:*:*:*:*:*:*
- cpe:2.3:a:eucalyptus:eucalyptus:1.2:*:*:*:*:*:*:*
- cpe:2.3:a:eucalyptus:eucalyptus:1.3:*:*:*:*:*:*:*
- cpe:2.3:a:eucalyptus:eucalyptus:1.4:*:*:*:*:*:*:*
- cpe:2.3:a:eucalyptus:eucalyptus:1.5.1:*:*:*:*:*:*:*
- cpe:2.3:a:eucalyptus:eucalyptus:1.5.2:*:*:*:*:*:*:*
- cpe:2.3:a:eucalyptus:eucalyptus:1.6:*:*:*:*:*:*:*
- cpe:2.3:a:eucalyptus:eucalyptus:1.6.2:*:*:*:*:*:*:*
- cpe:2.3:a:eucalyptus:eucalyptus:2.0:*:*:*:*:*:*:*
- cpe:2.3:a:eucalyptus:eucalyptus:2.0.0:*:*:*:*:*:*:*
- cpe:2.3:a:eucalyptus:eucalyptus:2.0.1:*:*:*:*:*:*:*
- cpe:2.3:a:eucalyptus:eucalyptus:2.0.2:*:*:*:*:*:*:*
- cpe:2.3:a:eucalyptus:eucalyptus:2.0.3:*:*:*:*:*:*:*
- cpe:2.3:a:eucalyptus:eucalyptus:3.0:*:*:*:*:*:*:*
- cpe:2.3:a:eucalyptus:eucalyptus:3.0.1:*:*:*:*:*:*:*
- cpe:2.3:a:eucalyptus:eucalyptus:3.1.0:*:*:*:*:*:*:*
- cpe:2.3:a:eucalyptus:eucalyptus:3.1.1:*:*:*:*:*:*:*
- cpe:2.3:a:eucalyptus:eucalyptus:3.1.2:*:*:*:*:*:*:*
- cpe:2.3:a:eucalyptus:eucalyptus:3.2.0:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- www.eucalyptus.com/resources/security/advisories/esa-10nvdVendor Advisory
- eucalyptus.atlassian.net/browse/EUCA-3074nvdVendor Advisory
News mentions
0No linked articles in our index yet.