Authentication Bypass Vulnerability in Apache CloudStack by Citrix
CVE-2014-7807

Currently unrated

Key Information:

Vendor
Apache
Vendor
CVE Published:
10 December 2014

Summary

Apache CloudStack versions prior to 4.3.2 and 4.4.2 present a vulnerability that allows attackers to bypass authentication controls via a login request that does not require a password. This exploitation results in an unauthenticated bind, potentially granting attackers unauthorized access to sensitive information or resources within the network.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.