MEDIUM
OnApp before 5.0.0-88, 5.5.0-93, and 6.0.0-196 allows an attacker to run arbitrary commands with root privileges on servers managed by OnApp for XEN/KVM hypervisors
Published Jun 19, 2019
6.6
MEDIUMCVSS 3.0
EPSS 1.53%
Description
OnApp before 5.0.0-88, 5.5.0-93, and 6.0.0-196 allows an attacker to run arbitrary commands with root privileges on servers managed by OnApp for XEN/KVM hypervisors. To exploit the vulnerability an attacker has to have control of a single server on a given cloud (e.g. by renting one). From the source server, the attacker can craft any command and trigger the OnApp platform to execute that command with root privileges on a target server.
Affected products
No data.
OR
- 5.0.0
- 5.0.0
- 5.0.0
- 5.0.0
- 5.0.0
- 5.1.0
- 5.1.0
- 5.2.0
- 5.3.0
- 5.3.0
- 5.4.0
- 5.4.0
- 5.4.0
- 5.4.0
- 5.4.0
- 5.4.0
- 5.4.0
- 5.5.0
- 5.5.0
- 5.5.0
- 5.5.0
- 5.5.0
- 5.5.0
- 5.5.0
- 5.5.0
- 5.5.0
- 5.5.0
- 5.6.0
- 5.6.0
- 5.7.0
- 5.8.0
- 5.9.0
- 5.10.0
- 6.0
- 6.0
- 6.0
- 6.0
- 6.0
- 6.0
- 6.0.0
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (0)
No CWE recorded.
References (3)
- https://docs.onapp.com/rn/general-security-advisory x_refsource_CONFIRMMitigationPatchRelease NotesVendor Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-4087 Advisory
- https://skylightcyber.com/2019/06/07/all-your-cloud-are-belong-to-us-cve-2019-12491/ x_refsource_MISCThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://docs.onapp.com/rn/general-security-advisory | x_refsource_CONFIRMMitigationPatchRelease NotesVendor Advisory | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-4087 | Advisory | |
| https://skylightcyber.com/2019/06/07/all-your-cloud-are-belong-to-us-cve-2019-12491/ | x_refsource_MISCThird Party Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jun 19, 2019
Updated Aug 4, 2024
Reserved May 30, 2019
Link CVE-2019-12491
CISA Vulnrichment
No data
Red Hat
No data
GitHub
No data