HPE Helion Eucalyptus 3.4.0 through 4.2.0 allows remote authenticated users to bypass an intended AssumeRole permission requirement and assume an IAM role by leveraging a policy setting for a user's account.
2016-01-05T11:59:07.597
2025-04-12T10:46:40.837
Deferred
CVSSv3.0: 7.5 (HIGH)
AV:N/AC:H/Au:S/C:P/I:P/A:P
3.9
6.4
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | eucalyptus | eucalyptus | 3.4.0 | Yes |
| Application | eucalyptus | eucalyptus | 3.4.1 | Yes |
| Application | eucalyptus | eucalyptus | 3.4.2 | Yes |
| Application | eucalyptus | eucalyptus | 3.4.3 | Yes |
| Application | eucalyptus | eucalyptus | 4.0.0 | Yes |
| Application | eucalyptus | eucalyptus | 4.0.1 | Yes |
| Application | eucalyptus | eucalyptus | 4.0.2 | Yes |
| Application | eucalyptus | eucalyptus | 4.1.0 | Yes |
| Application | eucalyptus | eucalyptus | 4.1.1 | Yes |
| Application | eucalyptus | eucalyptus | 4.1.2 | Yes |
| Application | eucalyptus | eucalyptus | 4.2.0 | Yes |