VYPR
High severity7.3NVD Advisory· Published Apr 4, 2024· Updated Jun 17, 2026

CVE-2024-29007

CVE-2024-29007

Description

The CloudStack management server and secondary storage VM could be tricked into making requests to restricted or random resources by means of following 301 HTTP redirects presented by external servers when downloading templates or ISOs. Users are recommended to upgrade to version 4.18.1.1 or 4.19.0.1, which fixes this issue.

Affected products

4
  • Apache/Cloudstack4 versions
    cpe:2.3:a:apache:cloudstack:*:*:*:*:*:*:*:*+ 3 more
    • cpe:2.3:a:apache:cloudstack:*:*:*:*:*:*:*:*range: >=4.9.1.0,<4.18.1.1
    • cpe:2.3:a:apache:cloudstack:4.19.0.0:*:*:*:*:*:*:*
    • (no CPE)range: <=4.19.0.0
    • (no CPE)range: 4.9.1.0

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.