Eucalyptus is a niche, open-source cloud-infrastructure platform that provides AWS-compatible compute, storage, and networking services for on-premises deployments. Its vulnerability footprint concentrates across the core Eucalyptus platform, its management console, and the Eustore component, and recurs through weakness classes including sensitive information exposure, authentication failures, input-validation gaps, and cross-site scripting that are characteristic of large web-facing and API-driven cloud systems. The exposure reflects the authentication and request-handling complexity inherent to a platform that must mediate access to virtualized resources and enforce isolation across tenants. Defenders tracking cloud-infrastructure deployments should inventory instances of this platform and prioritize patching of the management interfaces, as they typically represent administrative and data-access control points. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Eucalyptus over time
Signals from CVEs in this vendor scope (25 CVEs).
25 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2014-5039CRITICAL Cross-site scripting (XSS) vulnerability in Eucalyptus Management Console (EMC) 4.0.x before 4.0.2 allows remote attackers to inject arbitrary web script or HTML via unspecified ve | Jan 31, 2020 | 9.6 | 30 | NO | NO |
CVE-2013-4767HIGH Unspecified vulnerability in Eucalyptus before 3.3.2 has unknown impact and attack vectors. | Oct 10, 2013 | 10.0 | 25 | NO | NO |
CVE-2012-3240HIGH The Walrus service in Eucalyptus 2.0.3 and 3.0.x before 3.0.2 allows remote attackers to gain administrator privileges via a crafted REST request. | Jul 17, 2012 | 7.5 | 24 | NO | NO |
CVE-2010-3905HIGH The password reset feature in the administrator interface for Eucalyptus 2.0.0 and 2.0.1 does not perform authentication, which allows remote attackers to gain privileges by sendin | Dec 22, 2010 | 7.5 | 24 | NO | NO |
CVE-2016-8528HIGH A Remote Escalation of Privilege vulnerability in HPE Helion Eucalyptus version 3.3.0 through 4.3.1 was found. | Feb 15, 2018 | 8.8 | 23 | NO | NO |
CVE-2012-3241HIGH The VMware Broker in Eucalyptus 2.0.3 and 3.0.x before 3.0.2 does not properly authenticate SOAP requests, which allows remote attackers to execute arbitrary VMware Broker API comm | Jul 17, 2012 | 7.5 | 23 | NO | NO |
CVE-2016-8520HIGH HPE Helion Eucalyptus v4.3.0 and earlier does not correctly check IAM user's permissions for accessing versioned objects and ACLs. In some cases, authenticated users with S3 permis | Feb 15, 2018 | 8.8 | 22 | NO | NO |
CVE-2017-7999MEDIUM Atlassian Eucalyptus before 4.4.1, when in EDGE mode, allows remote authenticated users with certain privileges to cause a denial of service (E2 service outage) via unspecified vec | Jun 1, 2017 | 6.5 | 22 | NO | NO |
CVE-2014-5040MEDIUM HP Helion Eucalyptus 4.1.x before 4.1.2 and HPE Helion Eucalyptus 4.2.x before 4.2.1 allow remote authenticated users to bypass intended access restrictions and modify arbitrary (1 | Jan 5, 2016 | 6.8 | 22 | NO | NO |
CVE-2011-0730MEDIUM Eucalyptus before 2.0.3 and Eucalyptus EE before 2.0.2, as used in Ubuntu Enterprise Cloud (UEC) and other products, do not properly interpret signed elements in SOAP requests, whi | Jun 2, 2011 | 6.5 | 22 | NO | NO |
Signals from CVEs in this vendor scope (25 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Eucalyptus.
Media articles that mention a CVE ID that affects a product developed by Eucalyptus — matched by CVE ID, not by vendor name.