cbcvebase.

Apache Software Foundation Apache Cloudstack vulnerabilities

31 known vulnerabilities affecting apache_software_foundation/apache_cloudstack.

Total CVEs
31
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL7HIGH13MEDIUM11

Vulnerabilities

Page 2 of 2
CVE-2025-66170P3MEDIUMCVSS 6.5≥ 4.21.0.0, ≤ 4.22.0.02026-05-08
CVE-2025-66170 [MEDIUM] CWE-863 CVE-2025-66170: The CloudStack Backup plugin has an improper authorization logic in versions 4.21.0.0 and 4.22.0.0. The CloudStack Backup plugin has an improper authorization logic in versions 4.21.0.0 and 4.22.0.0. Anyone with authenticated user-account access in CloudStack 4.21.0.0+ environments, where this plugin is enabled and has access to specific APIs can list backups from any account in the environment. This vulnerability does not allow them to see the con
nvd
CVE-2024-29008P3MEDIUMCVSS 6.4≥ 4.14.0.0, ≤ 4.18.1.0v4.19.0.02024-04-04
CVE-2024-29008 [MEDIUM] CWE-20 CVE-2024-29008: A problem has been identified in the CloudStack additional VM configuration (extraconfig) feature wh A problem has been identified in the CloudStack additional VM configuration (extraconfig) feature which can be misused by anyone who has privilege to deploy a VM instance or configure settings of an already deployed VM instance, to configure additional VM configuration even when the feature is not explicitly enabled by the administrator. In a KVM bas
nvd
CVE-2024-45462P4HIGHCVSS 7.1≥ 4.15.1.0, ≤ 4.18.2.3≥ 4.19.0.0, ≤ 4.19.1.12024-10-16
CVE-2024-45462 [HIGH] CWE-613 CVE-2024-45462: The logout operation in the CloudStack web interface does not expire the user session completely whi The logout operation in the CloudStack web interface does not expire the user session completely which is valid until expiry by time or restart of the backend service. An attacker that has access to a user's browser can use an unexpired session to gain access to resources owned by the logged out user account. This issue affects Apache CloudStack from
nvd
CVE-2025-69233P4MEDIUMCVSS 5.3≥ 4.0.0, ≤ 4.20.2.0≥ 4.21.0.0, ≤ 4.22.0.02026-05-08
CVE-2025-69233 [MEDIUM] CWE-367 CVE-2025-69233: Due to multiple time-of-check time-of-use race conditions in the resource count check and increment Due to multiple time-of-check time-of-use race conditions in the resource count check and increment logic, as well as missing validations, users of the platform are able to exceed the allocation limits configured for their accounts/domains. This can be used by an attacker to degrade the infrastructure's resources and lead to denial of service conditi
nvd
CVE-2025-30675P4MEDIUMCVSS 4.7≥ 4.0.0, < 4.19.3.0≥ 4.20.0.0, < 4.20.1.02025-06-11
CVE-2025-30675 [MEDIUM] CWE-200 CVE-2025-30675: In Apache CloudStack, a flaw in access control affects the listTemplates and listIsos APIs. A malici In Apache CloudStack, a flaw in access control affects the listTemplates and listIsos APIs. A malicious Domain Admin or Resource Admin can exploit this issue by intentionally specifying the 'domainid' parameter along with the 'filter=self' or 'filter=selfexecutable' values. This allows the attacker to gain unauthorized visibility into templates and
nvd
CVE-2025-22828P4MEDIUMCVSS 4.3≥ 4.16.0, ≤ *2025-01-13
CVE-2025-22828 [MEDIUM] CWE-200 CVE-2025-22828: CloudStack users can add and read comments (annotations) on resources they are authorised to access. CloudStack users can add and read comments (annotations) on resources they are authorised to access. Due to an access validation issue that affects Apache CloudStack versions from 4.16.0, users who have access, prior access or knowledge of resource UUIDs can list and add comments (annotations) to such resources. An attacker with a user-account and
nvd
CVE-2025-59302P4MEDIUMCVSS 4.7≥ 4.18.0, < 4.20.2≥ 4.21.0, < 4.22.02025-11-27
CVE-2025-59302 [MEDIUM] CWE-94 CVE-2025-59302: In Apache CloudStack improper control of generation of code ('Code Injection') vulnerability is fou In Apache CloudStack improper control of generation of code ('Code Injection') vulnerability is found in the following APIs which are accessible only to admins. * quotaTariffCreate * quotaTariffUpdate * createSecondaryStorageSelector * updateSecondaryStorageSelector * updateHost * updateStorage This issue affects Apache CloudStack: from 4.18.0 befo
nvd
CVE-2025-22829P4MEDIUMCVSS 4.3≥ 4.20.0.0, < 4.20.1.02025-06-10
CVE-2025-22829 [MEDIUM] CWE-269 CVE-2025-22829: The CloudStack Quota plugin has an improper privilege management logic in version 4.20.0.0. Anyone w The CloudStack Quota plugin has an improper privilege management logic in version 4.20.0.0. Anyone with authenticated user-account access in CloudStack 4.20.0.0 environments, where this plugin is enabled and have access to specific APIs can enable or disable reception of quota-related emails for any account in the environment and list their configur
nvd
CVE-2025-59454P4MEDIUMCVSS 4.3≥ 4.0.0, < 4.20.2≥ 4.21.0, < 4.22.02025-11-27
CVE-2025-59454 [MEDIUM] CWE-200 CVE-2025-59454: In Apache CloudStack, a gap in access control checks affected the APIs - createNetworkACL - listNetw In Apache CloudStack, a gap in access control checks affected the APIs - createNetworkACL - listNetworkACLs - listResourceDetails - listVirtualMachinesUsageHistory - listVolumesUsageHistory While these APIs were accessible only to authorized users, insufficient permission validation meant that users could occasionally access information beyond thei
nvd
CVE-2024-42222P4MEDIUMCVSS 4.3v4.19.1.02024-08-07
CVE-2024-42222 [MEDIUM] CWE-200 CVE-2024-42222: In Apache CloudStack 4.19.1.0, a regression in the network listing API allows unauthorised list acce In Apache CloudStack 4.19.1.0, a regression in the network listing API allows unauthorised list access of network details for domain admin and normal user accounts. This vulnerability compromises tenant isolation, potentially leading to unauthorised access to network details, configurations and data. Affected users are advised to upgrade to version
nvd
CVE-2013-4317P4MEDIUMCVSS 4.3v4.1.0, 4.1.12018-02-06
CVE-2013-4317 [MEDIUM] CWE-200 CVE-2013-4317: In Apache CloudStack 4.1.0 and 4.1.1, when calling the CloudStack API call listProjectAccounts as a In Apache CloudStack 4.1.0 and 4.1.1, when calling the CloudStack API call listProjectAccounts as a regular, non-administrative user, the user is able to see information for accounts other than their own.
nvd
Apache Software Foundation Apache Cloudstack vulnerabilities | cvebase