Apache CloudStack unauthenticated LDAP Binding Vulnerability
Release date:
Updated on:
Affected Systems:
Apache Group CloudStack <4.4.2
Apache Group CloudStack <4.3.2
Description:
CVE (CAN) ID: CVE-2014-7807
Apache CloudStack is an open source software for deploying and managing large virtual machine networks.
A security vulnerability exists in Apache CloudStack versions earlier than 4.3.2 and earlier than 4.4.2. Remote attackers can bypass authentication without entering a password.
<* Source: Citrix Security Team
Link: http://www.securityfocus.com/archive/1/archive/1/534176/100/0/threaded
*>
Suggestion:
Vendor patch:
Apache Group
------------
The vendor has released the Apache CloudStack 4.3.2 patch to fix this security problem. Please download it from the vendor's homepage:
Http://httpd.apache.org/
This article permanently updates the link address: