The virtual router in Apache CloudStack before 4.2.1 does not preserve the source restrictions in firewall rules after being restarted, which allows remote attackers to bypass intended restrictions via a request.
References
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2014-01-15 16:08
Updated : 2014-09-04 05:25
NVD link : CVE-2013-6398
Mitre link : CVE-2013-6398
CVE.ORG link : CVE-2013-6398
JSON object : View
Products Affected
apache
- cloudstack
CWE
CWE-264
Permissions, Privileges, and Access Controls