cbcvebase.

Apache Cloudstack vulnerabilities

64 known vulnerabilities affecting apache/cloudstack.

Total CVEs
64
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL12HIGH25MEDIUM24LOW3

Vulnerabilities

Page 3 of 4
CVE-2024-45461P3MEDIUMCVSS 6.3≥ 4.7.0, < 4.18.2.4≥ 4.19.0.0, < 4.19.1.22024-10-16
CVE-2024-45461 [MEDIUM] CWE-862 CVE-2024-45461: The CloudStack Quota feature allows cloud administrators to implement a quota or usage limit system The CloudStack Quota feature allows cloud administrators to implement a quota or usage limit system for cloud resources, and is disabled by default. In environments where the feature is enabled, due to missing access check enforcements, non-administrative CloudStack user accounts are able to access and modify quota-related configurations and data. Th
nvd
CVE-2024-29008P3MEDIUMCVSS 6.4≥ 4.14.0.0, < 4.18.1.1v4.19.0.02024-04-04
CVE-2024-29008 [MEDIUM] CWE-20 CVE-2024-29008: A problem has been identified in the CloudStack additional VM configuration (extraconfig) feature wh A problem has been identified in the CloudStack additional VM configuration (extraconfig) feature which can be misused by anyone who has privilege to deploy a VM instance or configure settings of an already deployed VM instance, to configure additional VM configuration even when the feature is not explicitly enabled by the administrator. In a KVM bas
nvd
CVE-2014-7807P3MEDIUMCVSS 5.0v4.3.0v4.3.1+2 more2014-12-10
CVE-2014-7807 [MEDIUM] CWE-287 CVE-2014-7807: Apache CloudStack 4.3.x before 4.3.2 and 4.4.x before 4.4.2 allows remote attackers to bypass authen Apache CloudStack 4.3.x before 4.3.2 and 4.4.x before 4.4.2 allows remote attackers to bypass authentication via a login request without a password, which triggers an unauthenticated bind.
nvd
CVE-2026-66797P4MEDIUMCVSS 5.4≥ 4.15.0.0, < 4.20.3.1≥ 4.21.0.0, < 4.22.1.12026-08-21
CVE-2026-66797 [MEDIUM] CWE-284 CVE-2026-66797: Improper access control in CloudStack's annotation functionality allows unauthorized comment creatio Improper access control in CloudStack's annotation functionality allows unauthorized comment creation and disclosure. The addAnnotation and listAnnotation APIs perform an ownership check when an entity's UUID is specified, but fail to honor its result correctly. This lets any authenticated user write annotations to, and disclose existing annotatio
nvd
CVE-2013-2758P4MEDIUMCVSS 5.0v4.0.0v4.0.1+1 more2014-05-23
CVE-2013-2758 [MEDIUM] CWE-310 CVE-2013-2758: Apache CloudStack 4.0.0 before 4.0.2 and Citrix CloudPlatform (formerly Citrix CloudStack) 3.0.x bef Apache CloudStack 4.0.0 before 4.0.2 and Citrix CloudPlatform (formerly Citrix CloudStack) 3.0.x before 3.0.6 Patch C uses a hash of a predictable sequence, which makes it easier for remote attackers to guess the console access URL via a brute force attack.
nvd
CVE-2024-45462P4HIGHCVSS 7.1≥ 4.15.1.0, < 4.18.2.4≥ 4.19.0.0, < 4.19.1.22024-10-16
CVE-2024-45462 [HIGH] CWE-613 CVE-2024-45462: The logout operation in the CloudStack web interface does not expire the user session completely whi The logout operation in the CloudStack web interface does not expire the user session completely which is valid until expiry by time or restart of the backend service. An attacker that has access to a user's browser can use an unexpired session to gain access to resources owned by the logged out user account. This issue affects Apache CloudStack from
nvd
CVE-2014-9593P4MEDIUMCVSS 5.0≤ 4.3.1v4.4.0+1 more2015-01-15
CVE-2014-9593 [MEDIUM] CWE-200 CVE-2014-9593: Apache CloudStack before 4.3.2 and 4.4.x before 4.4.2 allows remote attackers to obtain private keys Apache CloudStack before 4.3.2 and 4.4.x before 4.4.2 allows remote attackers to obtain private keys via a listSslCerts API call.
nvd
CVE-2025-69233P4MEDIUMCVSS 5.3≥ 4.0.0, < 4.20.3.0≥ 4.21.0.0, < 4.22.0.12026-05-08
CVE-2025-69233 [MEDIUM] CWE-367 CVE-2025-69233: Due to multiple time-of-check time-of-use race conditions in the resource count check and increment Due to multiple time-of-check time-of-use race conditions in the resource count check and increment logic, as well as missing validations, users of the platform are able to exceed the allocation limits configured for their accounts/domains. This can be used by an attacker to degrade the infrastructure's resources and lead to denial of service conditi
nvd
CVE-2025-30675P4MEDIUMCVSS 4.7≥ 4.0.0, < 4.19.3.0≥ 4.20.0.0, < 4.20.1.02025-06-11
CVE-2025-30675 [MEDIUM] CWE-200 CVE-2025-30675: In Apache CloudStack, a flaw in access control affects the listTemplates and listIsos APIs. A malici In Apache CloudStack, a flaw in access control affects the listTemplates and listIsos APIs. A malicious Domain Admin or Resource Admin can exploit this issue by intentionally specifying the 'domainid' parameter along with the 'filter=self' or 'filter=selfexecutable' values. This allows the attacker to gain unauthorized visibility into templates and
nvd
CVE-2015-3251P4MEDIUMCVSS 4.9v4.4.4v4.5.12016-02-08
CVE-2015-3251 [MEDIUM] CWE-200 CVE-2015-3251: Apache CloudStack before 4.5.2 might allow remote authenticated administrators to obtain sensitive p Apache CloudStack before 4.5.2 might allow remote authenticated administrators to obtain sensitive password information for root accounts of virtual machines via unspecified vectors related to API calls.
nvd
CVE-2025-22828P4MEDIUMCVSS 4.3≥ 4.16.0.02025-01-13
CVE-2025-22828 [MEDIUM] CWE-200 CVE-2025-22828: CloudStack users can add and read comments (annotations) on resources they are authorised to access. CloudStack users can add and read comments (annotations) on resources they are authorised to access. Due to an access validation issue that affects Apache CloudStack versions from 4.16.0, users who have access, prior access or knowledge of resource UUIDs can list and add comments (annotations) to such resources. An attacker with a user-account and
nvd
CVE-2025-59302P4MEDIUMCVSS 4.7≥ 4.18.0.0, < 4.20.2.0v4.21.0.02025-11-27
CVE-2025-59302 [MEDIUM] CWE-94 CVE-2025-59302: In Apache CloudStack improper control of generation of code ('Code Injection') vulnerability is fou In Apache CloudStack improper control of generation of code ('Code Injection') vulnerability is found in the following APIs which are accessible only to admins. * quotaTariffCreate * quotaTariffUpdate * createSecondaryStorageSelector * updateSecondaryStorageSelector * updateHost * updateStorage This issue affects Apache CloudStack: from 4.18.0 befo
nvd
CVE-2025-22829P4MEDIUMCVSS 4.3v4.20.0.02025-06-10
CVE-2025-22829 [MEDIUM] CWE-269 CVE-2025-22829: The CloudStack Quota plugin has an improper privilege management logic in version 4.20.0.0. Anyone w The CloudStack Quota plugin has an improper privilege management logic in version 4.20.0.0. Anyone with authenticated user-account access in CloudStack 4.20.0.0 environments, where this plugin is enabled and have access to specific APIs can enable or disable reception of quota-related emails for any account in the environment and list their configur
nvd
CVE-2026-61422P4MEDIUMCVSS 4.3≥ 4.21.0.0, < 4.22.1.1v4.20.3.02026-08-21
CVE-2026-61422 [MEDIUM] CWE-918 CVE-2026-61422: Authenticated pre-validation SSRF vulnerability in Apache CloudStack's template and ISO registration Authenticated pre-validation SSRF vulnerability in Apache CloudStack's template and ISO registration functionality. When registering a template or ISO, CloudStack makes a live HTTP HEAD/GET call to determine file size for secondary storage usage-limit checks, and this happens before URL validation is performed. However, this does not pose a malicio
nvd
CVE-2026-61399P4MEDIUMCVSS 4.8≥ 4.20.0.0, < 4.20.3.1≥ 4.21.0.0, < 4.22.1.12026-08-21
CVE-2026-61399 [MEDIUM] CWE-116 CVE-2026-61399: Improper Encoding or Escaping of Output vulnerability in Apache CloudStack's UI while using Lock Use Improper Encoding or Escaping of Output vulnerability in Apache CloudStack's UI while using Lock User Functionality. This issue affects Apache CloudStack: from 4.20.0.0 through 4.20.3.0 and from 4.21.0.0 through 4.22.1.0. Users are recommended to upgrade to version 4.20.3.1 or 4.22.1.1 or later, which fixes the issue.
nvd
CVE-2024-42222P4MEDIUMCVSS 4.3v4.19.1.02024-08-07
CVE-2024-42222 [MEDIUM] CWE-200 CVE-2024-42222: In Apache CloudStack 4.19.1.0, a regression in the network listing API allows unauthorised list acce In Apache CloudStack 4.19.1.0, a regression in the network listing API allows unauthorised list access of network details for domain admin and normal user accounts. This vulnerability compromises tenant isolation, potentially leading to unauthorised access to network details, configurations and data. Affected users are advised to upgrade to version
nvd
CVE-2025-59454P4MEDIUMCVSS 4.3≥ 4.0.0, < 4.20.2.0v4.21.0.02025-11-27
CVE-2025-59454 [MEDIUM] CWE-200 CVE-2025-59454: In Apache CloudStack, a gap in access control checks affected the APIs - createNetworkACL - listNetw In Apache CloudStack, a gap in access control checks affected the APIs - createNetworkACL - listNetworkACLs - listResourceDetails - listVirtualMachinesUsageHistory - listVolumesUsageHistory While these APIs were accessible only to authorized users, insufficient permission validation meant that users could occasionally access information beyond thei
nvd
CVE-2013-6398P4LOWCVSS 2.8≤ 4.2.0v2.0+33 more2014-01-15
CVE-2013-6398 [LOW] CWE-264 CVE-2013-6398: The virtual router in Apache CloudStack before 4.2.1 does not preserve the source restrictions in fi The virtual router in Apache CloudStack before 4.2.1 does not preserve the source restrictions in firewall rules after being restarted, which allows remote attackers to bypass intended restrictions via a request.
nvd
CVE-2013-2136P4MEDIUMCVSS 4.3≤ 4.1.0v2.0+31 more2013-08-19
CVE-2013-2136 [MEDIUM] CWE-79 CVE-2013-2136: Multiple cross-site scripting (XSS) vulnerabilities in Apache CloudStack before 4.1.1 allow remote a Multiple cross-site scripting (XSS) vulnerabilities in Apache CloudStack before 4.1.1 allow remote attackers to inject arbitrary web script or HTML via the (1) Physical network name to the Zone wizard; (2) New network name, (3) instance name, or (4) group to the Instance wizard; (5) unspecified "multi-edit fields;" and (6) unspecified "list view" edit
nvd
CVE-2026-65613P4MEDIUMCVSS 4.3≥ 4.20.0.0, < 4.20.3.1≥ 4.21.0.0, < 4.22.1.12026-08-21
CVE-2026-65613 [MEDIUM] CWE-200 CVE-2026-65613: Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache CloudStack's Webh Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache CloudStack's Webhook module while listing and deleting deliveries. This issue affects Apache CloudStack: from 4.20.0.0 through 4.20.3.0 and from 4.21.0.0 through 4.22.1.0. Users are recommended to upgrade to version 4.20.3.1 or 4.22.1.1 or later, which fixes the iss
nvd
Apache Cloudstack vulnerabilities | cvebase