Apache

Cloudstack

64 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS -
  • Veröffentlicht 21.08.2026 08:25:23
  • Zuletzt bearbeitet 21.08.2026 09:16:39

Improper Encoding or Escaping of Output vulnerability in Apache CloudStack's UI while using Lock User Functionality. This issue affects Apache CloudStack: from 4.20.0.0 through 4.20.3.0 and from 4.21.0.0 through 4.22.1.0. Users are recommended to u...

  • EPSS -
  • Veröffentlicht 21.08.2026 08:25:02
  • Zuletzt bearbeitet 21.08.2026 09:16:39

Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache CloudStack's run and get diagnostics functionality for the system VMs and virtual routers. An authenticated user holding the permissions requ...

  • EPSS -
  • Veröffentlicht 21.08.2026 08:24:38
  • Zuletzt bearbeitet 21.08.2026 09:16:39

Authenticated pre-validation SSRF vulnerability in Apache CloudStack's template and ISO registration functionality. When registering a template or ISO, CloudStack makes a live HTTP HEAD/GET call to determine file size for secondary storage usage-lim...

  • EPSS -
  • Veröffentlicht 21.08.2026 08:23:55
  • Zuletzt bearbeitet 21.08.2026 09:16:39

Improper Access Control vulnerability in Apache CloudStack's Kubernetes Service (CKS) plugin, allowing cross-tenant manipulation of the Kubernetes cluster while adding and removing nodes. This issue affects Apache CloudStack: from 4.21.0.0 through 4...

  • EPSS -
  • Veröffentlicht 21.08.2026 08:23:30
  • Zuletzt bearbeitet 21.08.2026 09:16:40

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache CloudStack's Webhook module while listing and deleting deliveries. This issue affects Apache CloudStack: from 4.20.0.0 through 4.20.3.0 and from 4.21.0.0 through 4.22...

  • EPSS -
  • Veröffentlicht 21.08.2026 08:23:00
  • Zuletzt bearbeitet 21.08.2026 09:16:40

Missing authorization issue for domain admins in CloudStack's host tags listing functionality. Domain Admins, by default, have permission to call the listHostTags API, but the API returns host tags for every host in the environment without domain...

  • EPSS -
  • Veröffentlicht 21.08.2026 08:22:36
  • Zuletzt bearbeitet 21.08.2026 09:16:40

Improper authorization for CRUD operations on Project Roles and Project Role permissions for domain admins in CloudStack. A Domain Admin can create, update, delete, and list project roles and project role permissions for projects in any domain, n...

  • EPSS -
  • Veröffentlicht 21.08.2026 08:21:58
  • Zuletzt bearbeitet 21.08.2026 09:16:40

Improper access control in CloudStack's annotation functionality allows unauthorized comment creation and disclosure. The addAnnotation and listAnnotation APIs perform an ownership check when an entity's UUID is specified, but fail to honor its r...

  • EPSS -
  • Veröffentlicht 21.08.2026 08:21:29
  • Zuletzt bearbeitet 21.08.2026 09:16:40

Certificate validation failures in SAML authentication in Apache CloudStack 4.20.3.0 and 4.22.1.0 on all platforms allow a malicious agent to forge a SAML response to the management server. The agent will have to spoof the ip address of the IdP or ge...

  • EPSS 0.5%
  • Veröffentlicht 08.05.2026 12:22:56
  • Zuletzt bearbeitet 09.05.2026 07:16:09

Instances deployed via the Proxmox extension allow unauthorized access to instances belonging to other tenants. This issue affects Apache CloudStack: from 4.21.0.0 through 4.22.0.0. The Proxmox extension for CloudStack improperly uses a user-...