PT-2026-79331 · Apache · Cloudstack
CVSS v3.1
7.2
High
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Apache CloudStack versions 4.15.0.0 through 4.20.3.0
Apache CloudStack versions 4.21.0.0 through 4.22.1.0
Description
Improper authorization exists for CRUD (Create, Read, Update, Delete) operations on Project Roles and Project Role permissions for domain admins. A Domain Admin can create, update, delete, and list project roles and permissions for projects in any domain, regardless of whether the project belongs to their own domain or subdomain. The system only verifies that the caller is a Domain Admin but fails to validate the ownership of the target project, allowing a malicious Domain Admin to tamper with roles and permissions across unrelated domains.
Recommendations
Upgrade versions 4.15.0.0 through 4.20.3.0 to version 4.20.3.1 or later.
Upgrade versions 4.21.0.0 through 4.22.1.0 to version 4.22.1.1 or later.
Exploit
Fix
Improper Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cloudstack