--BXVAT5kNtrzKuDFl
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
Product: Apache CloudStack
Vendor: The Apache Software Foundation
Vulnerability Type(s): Cross-site scripting (XSS)
Vulnerable version(s): Apache CloudStack versions 4.0.0-incubating,
4.0.1-incubating, 4.0.2 and 4.1.0
CVE References: CVE-2013-2136
Risk Level: Low
CVSSv2 Base Scores: 4 (AV:N/AC:L/Au:S/C:N/I:P/A:N)
Description:
The Apache CloudStack Security Team was notified of an issue found in
the Apache CloudStack user interface that allows an authenticated user
to execute cross-site scripting attack against other users within the
system.
Mitigation:
Updating to Apache CloudStack versions 4.1.1 or higher will mitigate
this vulnerability.
Please see the 4.1.1 release notes for further information about how to
upgrade:
http://cloudstack.apache.org/docs/en-US/Apache_CloudStack/4.1.1/html/Release_Notes/index.html
References:
https://issues.apache.org/jira/browse/CLOUDSTACK-2936
--BXVAT5kNtrzKuDFl
Content-Type: application/pgp-signature
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.12 (Darwin)
Comment: GPGTools - http://gpgtools.org
iQIcBAEBAgAGBQJSARmaAAoJEJQ9mB+pml1YN1EQALxIJzq6OuNRJnhdJRjJqHG8
PWlkW7d0giu3qTKrfK4xMrhlHyt3U5PIaU6uuOd7Y0Pd7eMFW6KHDoLr3tSxie/A
Gh7JZb8JW0AK5cN8WmIAAIy8Enh+MkuJ8MSGhbmjQo+r+SZzm0eTvjKT27TPsXhp
I6bbbNJs1EjR+aGALFtJVyc5OGTUShOLGOgpBBbfDFSj+Um5VIhp438wZUJfiCp6
H6JC2GbBdQ5aA5bx1Qfz81EmBhZF21o8U++rxDbqgJcVrPuG+3SkQwaUrco/2BdQ
CcJlN763DKlqIDyr+UPT7j9Mkd3qgZIg0bJXND799HXCTNTZp4iCZdimz7wemiEt
vU75VhoNzBdDDuldXFR7epwQuQ19aB4Ba2iHy32q132xUIp8pkRfTgWSoZSYEpWX
WrkniWpuEh67pOtiAmoXRbPjoEo/qM7Unh7dZ4QQBLIzj78KQEi1lScKrbLzFApJ
JgYujgyJjMliyhWhUnvx4fdD7aQgdaL2qXbEf+yDZ5pikfZNzWVisSpAQb54xson
s/vp+m+kqnBK6caB1g0ayHTCSayrRqLDWF02DeMer+XncvM5tLD4q3a4IEHOIV/u
65SWmuU5DUtut5fgrRk25rkV/jlh8cVF0w74k4VGOcAMl2oE3fX1ES55SCLcD1B2
+YKS+FqEVV5SJzUowbpn
=Axyq
-----END PGP SIGNATURE-----
--BXVAT5kNtrzKuDFl--