CVE-2012-4066
Eucalyptus < 3.2.0 - Improper Authentication in Walrus Internal Message Protocol
Title source: llmDescription
The internal message protocol for Walrus in Eucalyptus 3.2.0 and earlier does not require signatures for unspecified request headers, which allows attackers to (1) delete or (2) upload snapshots.
References (1)
Core 1
Core References
Vendor Advisory x_refsource_confirm
http://www.eucalyptus.com/eucalyptus-cloud/security/esa-08
Scores
EPSS
0.0114
EPSS Percentile
62.7%
Details
CWE
CWE-287
Status
published
Products (18)
eucalyptus/eucalyptus
1.0
eucalyptus/eucalyptus
1.1
eucalyptus/eucalyptus
1.2
eucalyptus/eucalyptus
1.3
eucalyptus/eucalyptus
1.4
eucalyptus/eucalyptus
1.5.1
eucalyptus/eucalyptus
1.5.2
eucalyptus/eucalyptus
1.6
eucalyptus/eucalyptus
1.6.2
eucalyptus/eucalyptus
2.0
... and 8 more
Published
Mar 08, 2013
Tracked Since
Feb 18, 2026