VYPR

Cloudstack

by Apache

Source repositories

CVEs (45)

  • CVE-2025-69233MedMay 8, 2026
    risk 0.42cvss 6.5epss 0.00

    Due to multiple time-of-check time-of-use race conditions in the resource count check and increment logic, as well as missing validations, users of the platform are able to exceed the allocation limits configured for their accounts/domains. This can be used by an attacker to…

  • CVE-2025-66171MedMay 8, 2026
    risk 0.42cvss 6.5epss 0.01

    The CloudStack Backup plugin has an improper access logic in versions 4.21.0.0 and 4.22.0.0. Anyone with authenticated user-account access in CloudStack 4.21.0.0+ environments, where this plugin is enabled and have access to specific APIs can create new VMs using backups of any…

  • CVE-2025-66170MedMay 8, 2026
    risk 0.42cvss 6.5epss 0.00

    The CloudStack Backup plugin has an improper authorization logic in versions 4.21.0.0 and 4.22.0.0. Anyone with authenticated user-account access in CloudStack 4.21.0.0+ environments, where this plugin is enabled and has access to specific APIs can list backups from any account…

  • CVE-2024-29008MedApr 4, 2024
    risk 0.42cvss 6.4epss 0.01

    A problem has been identified in the CloudStack additional VM configuration (extraconfig) feature which can be misused by anyone who has privilege to deploy a VM instance or configure settings of an already deployed VM instance, to configure additional VM configuration even when…

  • CVE-2016-3085MedJun 10, 2016
    risk 0.42cvss 6.5epss 0.03

    Apache CloudStack 4.5.x before 4.5.2.1, 4.6.x before 4.6.2.1, 4.7.x before 4.7.1.1, and 4.8.x before 4.8.0.1, when SAML-based authentication is enabled and used, allow remote attackers to bypass authentication and access the user interface via vectors related to the SAML plugin.

  • CVE-2024-42062HigAug 7, 2024
    risk 0.40cvss 7.2epss 0.01

    CloudStack account-users by default use username and password based authentication for API and UI access. Account-users can generate and register randomised API and secret keys and use them for the purpose of API-based automation and integrations. Due to an access permission…

  • CVE-2024-45462MedOct 16, 2024
    risk 0.34cvss 6.3epss 0.00

    The logout operation in the CloudStack web interface does not expire the user session completely which is valid until expiry by time or restart of the backend service. An attacker that has access to a user's browser can use an unexpired session to gain access to resources owned…

  • CVE-2015-3251MedFeb 8, 2016
    risk 0.32cvss 4.9epss 0.02

    Apache CloudStack before 4.5.2 might allow remote authenticated administrators to obtain sensitive password information for root accounts of virtual machines via unspecified vectors related to API calls.

  • CVE-2025-30675MedJun 11, 2025
    risk 0.31cvss 4.7epss 0.01

    In Apache CloudStack, a flaw in access control affects the listTemplates and listIsos APIs. A malicious Domain Admin or Resource Admin can exploit this issue by intentionally specifying the 'domainid' parameter along with the 'filter=self' or 'filter=selfexecutable' values. This…

  • CVE-2024-45461MedOct 16, 2024
    risk 0.30cvss 5.7epss 0.01

    The CloudStack Quota feature allows cloud administrators to implement a quota or usage limit system for cloud resources, and is disabled by default. In environments where the feature is enabled, due to missing access check enforcements, non-administrative CloudStack user…

  • CVE-2025-22829MedJun 10, 2025
    risk 0.28cvss 4.3epss 0.01

    The CloudStack Quota plugin has an improper privilege management logic in version 4.20.0.0. Anyone with authenticated user-account access in CloudStack 4.20.0.0 environments, where this plugin is enabled and have access to specific APIs can enable or disable reception of…

  • CVE-2025-22828MedJan 13, 2025
    risk 0.28cvss 4.3epss 0.02

    CloudStack users can add and read comments (annotations) on resources they are authorised to access.  Due to an access validation issue that affects Apache CloudStack versions from 4.16.0, users who have access, prior access or knowledge of resource UUIDs can list and add…

  • CVE-2024-42222MedAug 7, 2024
    risk 0.28cvss 4.3epss 0.01

    In Apache CloudStack 4.19.1.0, a regression in the network listing API allows unauthorised list access of network details for domain admin and normal user accounts. This vulnerability compromises tenant isolation, potentially leading to unauthorised access to network details,…

  • CVE-2013-4317MedFeb 6, 2018
    risk 0.28cvss 4.3epss 0.01

    In Apache CloudStack 4.1.0 and 4.1.1, when calling the CloudStack API call listProjectAccounts as a regular, non-administrative user, the user is able to see information for accounts other than their own.

  • CVE-2025-59302MedNov 27, 2025
    risk 0.24cvss 4.7epss 0.00

    In Apache CloudStack improper control of generation of code ('Code Injection') vulnerability is found in the following APIs which are accessible only to admins. * quotaTariffCreate * quotaTariffUpdate * createSecondaryStorageSelector * …

  • CVE-2025-59454MedNov 27, 2025
    risk 0.21cvss 4.3epss 0.00

    In Apache CloudStack, a gap in access control checks affected the APIs - createNetworkACL - listNetworkACLs - listResourceDetails - listVirtualMachinesUsageHistory - listVolumesUsageHistory While these APIs were accessible only to authorized users, insufficient permission…

  • CVE-2013-2758May 23, 2014
    risk 0.01cvss epss 0.06

    Apache CloudStack 4.0.0 before 4.0.2 and Citrix CloudPlatform (formerly Citrix CloudStack) 3.0.x before 3.0.6 Patch C uses a hash of a predictable sequence, which makes it easier for remote attackers to guess the console access URL via a brute force attack.

  • CVE-2012-4501Oct 26, 2012
    risk 0.01cvss epss 0.08

    Citrix Cloud.com CloudStack, and Apache CloudStack pre-release, allows remote attackers to make arbitrary API calls by leveraging the system user account, as demonstrated by API calls to delete VMs.

  • CVE-2014-9593Jan 15, 2015
    risk 0.00cvss epss 0.03

    Apache CloudStack before 4.3.2 and 4.4.x before 4.4.2 allows remote attackers to obtain private keys via a listSslCerts API call.

  • CVE-2014-7807Dec 10, 2014
    risk 0.00cvss epss 0.03

    Apache CloudStack 4.3.x before 4.3.2 and 4.4.x before 4.4.2 allows remote attackers to bypass authentication via a login request without a password, which triggers an unauthenticated bind.