看板 Bugtraq 關於我們 聯絡資訊
--BXVAT5kNtrzKuDFl Content-Type: text/plain; charset=us-ascii Content-Disposition: inline Product: Apache CloudStack Vendor: The Apache Software Foundation Vulnerability Type(s): Cross-site scripting (XSS) Vulnerable version(s): Apache CloudStack versions 4.0.0-incubating, 4.0.1-incubating, 4.0.2 and 4.1.0 CVE References: CVE-2013-2136 Risk Level: Low CVSSv2 Base Scores: 4 (AV:N/AC:L/Au:S/C:N/I:P/A:N) Description: The Apache CloudStack Security Team was notified of an issue found in the Apache CloudStack user interface that allows an authenticated user to execute cross-site scripting attack against other users within the system. Mitigation: Updating to Apache CloudStack versions 4.1.1 or higher will mitigate this vulnerability. Please see the 4.1.1 release notes for further information about how to upgrade: http://cloudstack.apache.org/docs/en-US/Apache_CloudStack/4.1.1/html/Release_Notes/index.html References: https://issues.apache.org/jira/browse/CLOUDSTACK-2936 --BXVAT5kNtrzKuDFl Content-Type: application/pgp-signature -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (Darwin) Comment: GPGTools - http://gpgtools.org iQIcBAEBAgAGBQJSARmaAAoJEJQ9mB+pml1YN1EQALxIJzq6OuNRJnhdJRjJqHG8 PWlkW7d0giu3qTKrfK4xMrhlHyt3U5PIaU6uuOd7Y0Pd7eMFW6KHDoLr3tSxie/A Gh7JZb8JW0AK5cN8WmIAAIy8Enh+MkuJ8MSGhbmjQo+r+SZzm0eTvjKT27TPsXhp I6bbbNJs1EjR+aGALFtJVyc5OGTUShOLGOgpBBbfDFSj+Um5VIhp438wZUJfiCp6 H6JC2GbBdQ5aA5bx1Qfz81EmBhZF21o8U++rxDbqgJcVrPuG+3SkQwaUrco/2BdQ CcJlN763DKlqIDyr+UPT7j9Mkd3qgZIg0bJXND799HXCTNTZp4iCZdimz7wemiEt vU75VhoNzBdDDuldXFR7epwQuQ19aB4Ba2iHy32q132xUIp8pkRfTgWSoZSYEpWX WrkniWpuEh67pOtiAmoXRbPjoEo/qM7Unh7dZ4QQBLIzj78KQEi1lScKrbLzFApJ JgYujgyJjMliyhWhUnvx4fdD7aQgdaL2qXbEf+yDZ5pikfZNzWVisSpAQb54xson s/vp+m+kqnBK6caB1g0ayHTCSayrRqLDWF02DeMer+XncvM5tLD4q3a4IEHOIV/u 65SWmuU5DUtut5fgrRk25rkV/jlh8cVF0w74k4VGOcAMl2oE3fX1ES55SCLcD1B2 +YKS+FqEVV5SJzUowbpn =Axyq -----END PGP SIGNATURE----- --BXVAT5kNtrzKuDFl--