Providing Free and Editor Tested Software Downloads
< HOME | TUTORIALS | GEEK-CADE| WEB TOOLS | YOUTUBE | NEWSLETTER | DEALS! | FORUMS | >

MajorGeeks.com - Talk nerdy to me.

Software Categories

All In One Tweaks
Android
Antivirus & Malware
Appearance
Back Up
Browsers
CD\DVD\Blu-Ray
Covert Ops
Drivers
Drives (SSD, HDD, USB)
Games
Graphics & Photos
Internet Tools
Linux Distros
MajorGeeks Windows Tweaks
Multimedia
Networking
Office & Productivity
System Tools

Other news

· How To and Tutorials
· Life Hacks and Reviews
· Way Off Base
· MajorGeeks Deals
· News
· Off Base
· Reviews



IObit Black Friday Sale

spread the word

· YouTube
· Facebook
· Instagram
· Twitter
· Pintrest
· RSS/XML Feeds
· News Blur
· Yahoo
· Symbaloo

about

· Top Freeware Picks
· Malware Removal
· Geektionary
· Useful Links
· About Us
· Copyright
· Privacy
· Terms of Service
· How to Uninstall

top downloads

1. GS Auto Clicker
2. Macrium Reflect FREE Edition
3. Smart Defrag
4. MusicBee
5. Microsoft Visual C++ 2015-2022 Redistributable Package
6. Sergei Strelec's WinPE
7. Mozilla Firefox
8. Visual C++ Redistributable Runtimes AIO Repack
9. Winslop
10. K-Lite Mega Codec Pack
More >>

top reads

Star How To Remove the Windows 11 Updated Start Menu

Star How To Disable Drag Tray

Star How To Permanently Delete Files Without Sending Them to the Recycle Bin in Windows 11

Star How To Repair Install Windows 11, and Keep All Your Files and Apps

Star How To Turn Off Folder Backup Syncing on OneDrive

Star AI Actions - What Are They and How To Enable/Disable Them

Star Microsoft Is Ending 3rd Party Printer Driver Support in 2026: How to Protect Old Printer Drivers

Star How To Stop Edge and Chrome Default Browser Prompts

Star How To Configure Allowed Apps for Controlled Folder Access

Star Pause or Disable Automatic App Updates in Microsoft Store


MajorGeeks.Com » News » October 2012 » CloudStack alert users to critical vulnerability

CloudStack alert users to critical vulnerability


Contributed by: Email on 10/09/2012 02:41 PM [ comments Comments ]


Citrix and the Apache Software Foundation have alerted users to a critical vulnerability in the CloudStack open source cloud infrastructure management software. All versions downloaded from the cloudstack.org site will be vulnerable. CloudStack is also an incubating Apache project but there have been no official releases from Apache of that project. If users have taken the source from the Apache project, that software will be vulnerable.

Details of the issue were disclosed on Sunday; it appears that the system had a configuration issue which meant that any use could execute arbitrary CloudStack API calls such as deleting all the VMs in the system. A workaround, detailed in the various announcements, involves logging into the MySQL database that backs the system and setting a random password on the cloud.user account.

The Apache CloudStack code has been updated with a fix for the issue and it is believed that the issue should not affect any upcoming releases of the incubating Apache CloudStack project; version 4.0 has currently been frozen and a release candidate is expected soon.






« HTTPS Everywhere 3.0 supports more sites · CloudStack alert users to critical vulnerability · Huge cannabis plant found in elderly couple's garden »




Comments
comments powered by Disqus

MajorGeeks.Com » News » October 2012 » CloudStack alert users to critical vulnerability

© 2000-2026 MajorGeeks.com
Powered by Contentteller® Business Edition