Wednesday, October 10, 2012
Critical vulnerability warned in Cloudstack
The Apache Foundation and Citrix have warnedof critical configuration vulnerability in the current version of the open source cloud infrastructure management software, CloudStack.
The vulnerability affects all versions of Cloudstack, including Citrix commercial version.
The issue could allow execution of arbitrary Cloudstack API calls, such as deletion of all virtual machines in a system.
No recognized exploits have been released for the vulnerability.
Mitigation against the vulnerability is possible by logging into the Cloudstack MySQL database, disabling the system user and setting a random password.
Cloudstack is one of the largest open source cloud infrastructure management systems together with Open Stack and Eucalyptus.
Incubated by the Apache Software foundation, Cloudstack counts over 50 large organisations such as Intel, BT, Alcatel-Lucent, Active State and Tata Communications among its technology partners.
In March this year, Citrix announcedthat it would abandon its OpenStack distribution in favour of the CloudStack operating system.

This article was written by: Rajesh Darvesh
He is a Ethical Hacking and Security Professional, with experience in various aspects of Information Security and Founder of The Hacker Voice Other than this : He is an Internet Activist, Strong supporter of Anonymous and Wikileaks you can Follow him on Twitter
Subscribe to:
Post Comments (Atom)
0 Responses to “Critical vulnerability warned in Cloudstack”
Post a Comment