CVE-2016-8520: Eucalyptus
High severity, CVSS 8.8. EPSS: 1.4% chance of exploitation in the next 30 days.
HPE Helion Eucalyptus v4.3.0 and earlier does not correctly check IAM user's permissions for accessing versioned objects and ACLs. In some cases, authenticated users with S3 permissions could also access versioned data.
Affected products
- Eucalyptus Eucalyptus: up to and including 4.3.0
Published 2018-02-15. Last modified 2026-06-17.