--82I3+IH0IqGh5yIs
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
Issued: August 6, 2013
Updated: August 7, 2013
Product: Apache CloudStack
Vendor: The Apache Software Foundation
Vulnerability Type(s): Cross-site scripting (XSS)
Vulnerable version(s): Apache CloudStack versions 4.0.0-incubating,
4.0.1-incubating, 4.0.2 and 4.1.0
CVE References: CVE-2013-2136
Risk Level: Low
CVSSv2 Base Scores: 4 (AV:N/AC:L/Au:S/C:N/I:P/A:N)
Description:
The Apache CloudStack Security Team was notified of an issue found in
the Apache CloudStack user interface that allows an authenticated user
to execute cross-site scripting attack against other users within the
system.
Mitigation:
Updating to Apache CloudStack versions 4.1.1 or higher will mitigate
this vulnerability.
Please see the 4.1.1 release notes for further information about how to
upgrade:
http://cloudstack.apache.org/docs/en-US/Apache_CloudStack/4.1.1/html/Release_Notes/index.html
References:
https://issues.apache.org/jira/browse/CLOUDSTACK-2936
Credit:
This issue was identified by Oleg Boytsev from strongserver.org.
--82I3+IH0IqGh5yIs
Content-Type: application/pgp-signature
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.12 (Darwin)
Comment: GPGTools - http://gpgtools.org
iQIcBAEBAgAGBQJSAlbYAAoJEJQ9mB+pml1YcHYP+gI1Fher0vtpqMYxldPzau8p
11uVRMsTkVhUOvUP+RSmPjHnJcHFuwV2LdDKc98x64v4oB+3TlcdMzy2h5q3DtOl
QzD7sVY8a1r0clfnCIfUpxHDGjfMEEyruxPPodxTvodShmZ7w3odD4uKblB018/i
kNx1jD+jQw77pSOpQJhtur8KBplFegYQLnHteZhVd9LOLejzSNl3g008o2Jr3egJ
s8zYjuoPsVZ6fUQ2cLbtxuekdMoURdjMzFA1q96bfgHlCYz53BuqmEG8o2Qmjg7z
pDg29aaPnbChoOx3g5tNDcAbWPhhm1fei0D4Vw2c14Wky9CdIk0B03K2ZxpJfHeD
kKeouLWeYBuj3GHJs18nsqNi5vOmT70jAVzXSb2Vv9UIsUqGotgnMnSTVqGnVI+J
3nMDKwQiGlwfGimQPvBZlR4tOMZsefiBUiuhW4Rer1xgk1k3k5mRO9kmb6S1kSOd
JouNIfA5KdyAHa+sLD65JuvNSopkVVX2Kt2FvIZzvWEbGCsiGbYXlien8cqclBHv
JFBI4J7CrAA9rdWj5Bc2h04uvBjopObMhckKYJhD5t+6yPJf4XVplWq2PBS8QzvB
y/a2J9nobtxe5CjaEI9w/VqzEq98/HJEEMn8c6umGsXZICHhrGOF8imCYkZ3A2m3
hCj57GNrJ9i2uFG0geod
=u2Bp
-----END PGP SIGNATURE-----
--82I3+IH0IqGh5yIs--