Apache Software Foundation Apache Cloudstack vulnerabilities

24 known vulnerabilities affecting apache_software_foundation/apache_cloudstack.

Total CVEs
24
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL6HIGH10MEDIUM7LOW1

Vulnerabilities

Page 2 of 2
CVE-2022-35741CRITICALCVSS 9.8≥ 4.5.0, < Apache CloudStack*2022-07-18
CVE-2022-35741 [CRITICAL] CWE-611 CVE-2022-35741: Apache CloudStack version 4.5.0 and later has a SAML 2.0 authentication Service Provider plugin whic Apache CloudStack version 4.5.0 and later has a SAML 2.0 authentication Service Provider plugin which is found to be vulnerable to XML external entity (XXE) injection. This plugin is not enabled by default and the attacker would require that this plugin be enabled to exploit the vulnerability. When the SAML 2.0 plugin is enabled in affected versio
cvelistv5nvd
CVE-2022-26779HIGHCVSS 7.5≥ Apache CloudStack, < 4.16.12022-03-15
CVE-2022-26779 [HIGH] CWE-338 CVE-2022-26779: Apache CloudStack prior to 4.16.1.0 used insecure random number generation for project invitation to Apache CloudStack prior to 4.16.1.0 used insecure random number generation for project invitation tokens. If a project invite is created based only on an email address, a random token is generated. An attacker with knowledge of the project ID and the fact that the invite is sent, could generate time deterministic tokens and brute force attempt to use
cvelistv5nvd
CVE-2016-6813CRITICALCVSS 9.8v4.1 to 4.8.1.0v4.9.0.02018-02-06
CVE-2016-6813 [CRITICAL] CVE-2016-6813: Apache CloudStack 4.1 to 4.8.1.0 and 4.9.0.0 contain an API call designed to allow a user to registe Apache CloudStack 4.1 to 4.8.1.0 and 4.9.0.0 contain an API call designed to allow a user to register for the developer API. If a malicious user is able to determine the ID of another (non-"root") CloudStack user, the malicious user may be able to reset the API keys for the other user, in turn accessing their account and resources.
cvelistv5nvd
CVE-2013-4317MEDIUMCVSS 4.3v4.1.0, 4.1.12018-02-06
CVE-2013-4317 [MEDIUM] CWE-200 CVE-2013-4317: In Apache CloudStack 4.1.0 and 4.1.1, when calling the CloudStack API call listProjectAccounts as a In Apache CloudStack 4.1.0 and 4.1.1, when calling the CloudStack API call listProjectAccounts as a regular, non-administrative user, the user is able to see information for accounts other than their own.
cvelistv5nvd