PT-2026-79316 · Apache · Cloudstack
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Apache CloudStack versions 4.14.0.0 through 4.20.3.0
Apache CloudStack versions 4.21.0.0 through 4.22.1.0
Description
An authenticated tenant can perform Server-Side Request Forgery (SSRF) by registering a template that points to a malicious metalink file containing internal targets, allowing the Secondary Storage VM to retrieve and persist this data. Additionally, a tenant with the default User role can achieve Remote Code Execution (RCE) as root on the KVM hypervisor host. This occurs when a user registers a VM template with the
directDownload variable set to true and a URL pointing to a .metalink file; the management server fetches the XML and dispatches the download to the KVM agent without re-validating the inner URLs against the scheme allowlist.Recommendations
For versions 4.14.0.0 through 4.20.3.0, upgrade to version 4.20.3.1 or later.
For versions 4.21.0.0 through 4.22.1.0, upgrade to version 4.22.1.1 or later.
Exploit
Fix
SSRF
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Cloudstack