Apache VCL is vulnerable to improper input verification. vulnerability level: severe.
Affected Versions include: 2.1, 2.2, 2.2.1, 2.3, and 2.3.1.
Solution:
Upgrade Apache VCL 2.3 and 2.3.1 to version 2.3.2 as soon as possible.
Upgrade Apache VCL 2.2 and 2.2.1 to version 2.2.2 as soon as possible.
Upgrade Apache VCL 2.1 to version 2.2.2 or 2.3.2 as soon as possible.
For detailed vulnerability description, see here.
Apache VCL is a self-service system that provides end users with a dedicated computing environment for remote access. Typical scenarios are data centers, physical blade servers, traditional rack servers, or virtual machines. VCL can also provide proxy access for independent machines.
VCL aims to allow users to use these computing resources for a limited time through the Web interface. The scheduling API can be used to automatically Manage Server Clusters and HPC clusters.