PT-2026-79317 · Apache · Cloudstack
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Apache CloudStack versions 4.18.0.0 through 4.20.3.0
Apache CloudStack versions 4.21.0.0 through 4.22.1.0
Description
Insufficient access control validation in several userdata-related APIs may allow unauthorized cross-tenant or cross-account access to userdata resources belonging to other tenants. The affected endpoints include 'deleteUserData', 'linkUserDataToTemplate', 'resetUserDataForVirtualMachine', 'deployVirtualMachine', and 'updateVirtualMachine'. Additionally, the 'deleteCniConfiguration' API lacks proper access validation.
Recommendations
Upgrade versions 4.18.0.0 through 4.20.3.0 to 4.20.3.1 or later.
Upgrade versions 4.21.0.0 through 4.22.1.0 to 4.22.1.1 or later.
Exploit
Fix
Information Disclosure
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Cloudstack