PT-2026-79385 · Apache · Cloudstack
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Apache CloudStack versions 4.7.0 through 4.20.3.0
Apache CloudStack versions 4.21.0.0 through 4.22.1.0
Description
A Missing Release of Resource after Effective Lifetime issue exists within the scoped global configuration functionality. This flaw affects various modules and plugins of the management server, such as Quota and Host-HA, causing a database connection leak. This can result in a denial of service (DoS) scenario for the management server.
Recommendations
Upgrade versions 4.7.0 through 4.20.3.0 to 4.20.3.1 or later.
Upgrade versions 4.21.0.0 through 4.22.1.0 to 4.22.1.1 or later.
Exploit
Fix
DoS
Missing Release of Resource after Effective Lifetime
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cloudstack