Apache CloudStack
cpe:2.3:a:apache:cloudstack:*:*:*:*:*:*:*
- >= 4.0.0, < 4.20.2
- >= 4.21.0, < 4.22.0
An access control vulnerability has been identified in Apache CloudStack versions 4.0.0 prior to 4.20.2 and 4.21.0 prior to 4.22.0. This vulnerability affects several APIs, including createNetworkACL, listNetworkACLs, listResourceDetails, listVirtualMachinesUsageHistory, and listVolumesUsageHistory. While these APIs are restricted to authorized users, the lack of proper permission validation allowed some users to access information beyond their intended limits.
Exploitation of this vulnerability could lead to unauthorized access to sensitive information through the affected APIs.
Users are advised to upgrade to Apache CloudStack 4.20.2.0 or 4.22.0.0, both of which address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.