CloudStack account-users by default use username and password based authentication for API and UI access. Account-users can generate and register randomised API and secret keys and use them for the purpose of API-based automation and integrations. Due to an access permission validation issue that affects Apache CloudStack versions 4.10.0 up to 4.19.1.0, domain admin accounts were found to be able to query all registered account-users API and secret keys in an environment, including that of a root admin. An attacker who has domain admin access can exploit this to gain root admin and other-account privileges and perform malicious operations that can result in compromise of resources integrity and confidentiality, data loss, denial of service and availability of CloudStack managed infrastructure.
Users are recommended to upgrade to Apache CloudStack 4.18.2.3 or 4.19.1.1, or later, which addresses this issue. Additionally, all account-user API and secret keys should be regenerated.
References
Link | Resource |
---|---|
https://cloudstack.apache.org/blog/security-release-advisory-4.19.1.1-4.18.2.3 | Vendor Advisory |
https://lists.apache.org/thread/lxqtfd6407prbw3801hb4fz3ot3t8wlj | Mailing List Release Notes |
https://www.shapeblue.com/shapeblue-security-advisory-apache-cloudstack-security-releases-4-18-2-3-and-4-19-1-1/ | Third Party Advisory |
Configurations
Configuration 1 (hide)
|
History
11 Oct 2024, 13:26
Type | Values Removed | Values Added |
---|---|---|
CWE |
19 Aug 2024, 14:15
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-863 |
12 Aug 2024, 18:56
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-276 | |
First Time |
Apache cloudstack
Apache |
|
References | () https://cloudstack.apache.org/blog/security-release-advisory-4.19.1.1-4.18.2.3 - Vendor Advisory | |
References | () https://lists.apache.org/thread/lxqtfd6407prbw3801hb4fz3ot3t8wlj - Mailing List, Release Notes | |
References | () https://www.shapeblue.com/shapeblue-security-advisory-apache-cloudstack-security-releases-4-18-2-3-and-4-19-1-1/ - Third Party Advisory | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.2 |
CPE | cpe:2.3:a:apache:cloudstack:*:*:*:*:*:*:*:* |
07 Aug 2024, 19:35
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 8.8 |
07 Aug 2024, 15:17
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
07 Aug 2024, 08:16
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-08-07 08:16
Updated : 2024-10-11 13:26
NVD link : CVE-2024-42062
Mitre link : CVE-2024-42062
CVE.ORG link : CVE-2024-42062
JSON object : View
Products Affected
apache
- cloudstack
CWE
CWE-863
Incorrect Authorization