Apache

Cloudstack

64 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS -
  • Veröffentlicht 21.08.2026 08:30:07
  • Zuletzt bearbeitet 21.08.2026 09:16:38

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Apache CloudStack's NAS backup provider plugin. The addBackupRepository API (available since 4.20.0.0) and updateBackupRepository API (introdu...

  • EPSS -
  • Veröffentlicht 21.08.2026 08:29:41
  • Zuletzt bearbeitet 21.08.2026 09:16:38

SSRF via Metalink Mirror URL Resolution: An authenticated tenant can register a template pointing to an attacker-controlled metalink file containing internal targets. The Secondary Storage VM will retrieve the data and persist it as a template file,...

  • EPSS -
  • Veröffentlicht 21.08.2026 08:29:17
  • Zuletzt bearbeitet 21.08.2026 09:16:38

Missing Authorization, Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache CloudStack's Userdata reference APIs. Several userdata-related APIs in Apache CloudStack, including deleteUserData, linkUserDataToTemplate, res...

  • EPSS -
  • Veröffentlicht 21.08.2026 08:28:51
  • Zuletzt bearbeitet 21.08.2026 09:16:38

Server-Side Request Forgery (SSRF) vulnerability in Apache CloudStack's webhook module, exploitable via webhook delivery requests. This issue affects Apache CloudStack: from 4.20.0.0 through 4.20.3.0 and from 4.21.0.0 through 4.22.1.0. Users are re...

  • EPSS -
  • Veröffentlicht 21.08.2026 08:28:14
  • Zuletzt bearbeitet 21.08.2026 09:16:38

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache CloudStack's OAuth authentication plugin while listing OAuth providers. This issue affects Apache CloudStack: from 4.19.0.0 through 4.20.3.0 and from 4.21.0.0 through...

  • EPSS -
  • Veröffentlicht 21.08.2026 08:27:53
  • Zuletzt bearbeitet 21.08.2026 09:16:38

Cleartext Storage of Sensitive Information vulnerability in Apache CloudStack with AsyncJob storage in the database. This issue affects Apache CloudStack: from 4.0.0 through 4.20.3.0 and from 4.21.0.0 through 4.22.1.0. Users are recommended to upgr...

  • EPSS -
  • Veröffentlicht 21.08.2026 08:27:16
  • Zuletzt bearbeitet 21.08.2026 09:16:38

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache CloudStack's LDAP authentication plugin while listing LDAP providers. LDAP configurations can be listed by any authenticated user with access to the listLda...

  • EPSS -
  • Veröffentlicht 21.08.2026 08:26:52
  • Zuletzt bearbeitet 21.08.2026 09:16:38

Improper Privilege Management vulnerability in Apache CloudStack's Two-factor authentication plugin allowing bypass of the two-factor authentication disable flow. This issue affects Apache CloudStack: from 4.18.0.0 through 4.20.3.0 and from 4.21.0.0...

  • EPSS -
  • Veröffentlicht 21.08.2026 08:26:25
  • Zuletzt bearbeitet 21.08.2026 09:16:39

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache CloudStack's OAuth2 authentication plugin and Google OAuth integration. This issue affects Apache CloudStack: from 4.19.0.0 through 4.20.3.0 and from 4.21.0.0 through...

  • EPSS -
  • Veröffentlicht 21.08.2026 08:25:47
  • Zuletzt bearbeitet 21.08.2026 09:16:39

Improper Encoding or Escaping of Output vulnerability in Apache CloudStack's UI while using Instance Reset Password functionality. This issue affects Apache CloudStack: from 4.15.1.0 through 4.20.3.0 and from 4.21.0.0 through 4.22.1.0. Users are re...