CVE-2022-26779
published 2022-03-15CVE-2022-26779: Apache CloudStack prior to 4.16.1.0 used insecure random number generation for project invitation tokens. If a project invite is created based only on an email…
PriorityP346high7.5CVSS 3.1
AVNACHPRLUINSUCHIHAH
EPSS
2.81%
84.9th percentile
Apache CloudStack prior to 4.16.1.0 used insecure random number generation for project invitation tokens. If a project invite is created based only on an email address, a random token is generated. An attacker with knowledge of the project ID and the fact that the invite is sent, could generate time deterministic tokens and brute force attempt to use them prior to the legitimate receiver accepting the invite. This feature is not enabled by default, the attacker is required to know or guess the project ID for the invite in addition to the invitation token, and the attacker would need to be an existing authorized user of CloudStack.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | cloudstack | < 4.16.1.0 | 4.16.1.0 |
| apache_software_foundation | apache_cloudstack | >= Apache CloudStack < 4.16.1 | 4.16.1 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.04.6MEDIUMAV:N/AC:H/Au:S/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No advisories linked to this vulnerability.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.openwall.com/lists/oss-security/2022/03/15/1https://github.com/JLLeitschuh/security-research/security/advisories/GHSA-vpcc-9rh2-8jfphttps://lists.apache.org/thread/dmm07b1cyosovqr12ddhkko501p11h2hhttp://www.openwall.com/lists/oss-security/2022/03/15/1https://github.com/JLLeitschuh/security-research/security/advisories/GHSA-vpcc-9rh2-8jfphttps://lists.apache.org/thread/dmm07b1cyosovqr12ddhkko501p11h2h
2022-03-15
Published