VYPR

Cloudstack

by Apache

Source repositories

CVEs (65)

  • CVE-2024-42062HigAug 7, 2024
    risk 0.40cvss 7.2epss 0.01

    CloudStack account-users by default use username and password based authentication for API and UI access. Account-users can generate and register randomised API and secret keys and use them for the purpose of API-based automation and integrations. Due to an access permission…

  • CVE-2026-66797MedAug 21, 2026
    risk 0.35cvss 5.4epss 0.00

    Improper access control in CloudStack's annotation functionality allows unauthorized comment creation and disclosure. The addAnnotation and listAnnotation APIs perform an ownership check when an entity's UUID is specified, but fail to honor its result correctly. This lets…

  • CVE-2024-45462MedOct 16, 2024
    risk 0.34cvss 6.3epss 0.00

    The logout operation in the CloudStack web interface does not expire the user session completely which is valid until expiry by time or restart of the backend service. An attacker that has access to a user's browser can use an unexpired session to gain access to resources owned…

  • CVE-2026-61399MedAug 21, 2026
    risk 0.31cvss 4.8epss 0.00

    Improper Encoding or Escaping of Output vulnerability in Apache CloudStack's UI while using Lock User Functionality. This issue affects Apache CloudStack: from 4.20.0.0 through 4.20.3.0 and from 4.21.0.0 through 4.22.1.0. Users are recommended to upgrade to version 4.20.3.1 or…

  • CVE-2025-30675MedJun 11, 2025
    risk 0.31cvss 4.7epss 0.01

    In Apache CloudStack, a flaw in access control affects the listTemplates and listIsos APIs. A malicious Domain Admin or Resource Admin can exploit this issue by intentionally specifying the 'domainid' parameter along with the 'filter=self' or 'filter=selfexecutable' values. This…

  • CVE-2024-45461MedOct 16, 2024
    risk 0.30cvss 5.7epss 0.01

    The CloudStack Quota feature allows cloud administrators to implement a quota or usage limit system for cloud resources, and is disabled by default. In environments where the feature is enabled, due to missing access check enforcements, non-administrative CloudStack user…

  • CVE-2026-65613MedAug 21, 2026
    risk 0.28cvss 4.3epss 0.00

    Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache CloudStack's Webhook module while listing and deleting deliveries. This issue affects Apache CloudStack: from 4.20.0.0 through 4.20.3.0 and from 4.21.0.0 through 4.22.1.0. Users are recommended…

  • CVE-2026-61422MedAug 21, 2026
    risk 0.28cvss 4.3epss 0.00

    Authenticated pre-validation SSRF vulnerability in Apache CloudStack's template and ISO registration functionality. When registering a template or ISO, CloudStack makes a live HTTP HEAD/GET call to determine file size for secondary storage usage-limit checks, and this happens…

  • CVE-2025-22829MedJun 10, 2025
    risk 0.28cvss 4.3epss 0.01

    The CloudStack Quota plugin has an improper privilege management logic in version 4.20.0.0. Anyone with authenticated user-account access in CloudStack 4.20.0.0 environments, where this plugin is enabled and have access to specific APIs can enable or disable reception of…

  • CVE-2025-22828MedJan 13, 2025
    risk 0.28cvss 4.3epss 0.02

    CloudStack users can add and read comments (annotations) on resources they are authorised to access.  Due to an access validation issue that affects Apache CloudStack versions from 4.16.0, users who have access, prior access or knowledge of resource UUIDs can list and add…

  • CVE-2024-42222MedAug 7, 2024
    risk 0.28cvss 4.3epss 0.01

    In Apache CloudStack 4.19.1.0, a regression in the network listing API allows unauthorised list access of network details for domain admin and normal user accounts. This vulnerability compromises tenant isolation, potentially leading to unauthorised access to network details,…

  • CVE-2013-4317MedFeb 6, 2018
    risk 0.28cvss 4.3epss 0.01

    In Apache CloudStack 4.1.0 and 4.1.1, when calling the CloudStack API call listProjectAccounts as a regular, non-administrative user, the user is able to see information for accounts other than their own.

  • CVE-2015-3251MedFeb 8, 2016
    risk 0.25cvss 4.9epss 0.02

    Apache CloudStack before 4.5.2 might allow remote authenticated administrators to obtain sensitive password information for root accounts of virtual machines via unspecified vectors related to API calls.

  • CVE-2025-59302MedNov 27, 2025
    risk 0.24cvss 4.7epss 0.00

    In Apache CloudStack improper control of generation of code ('Code Injection') vulnerability is found in the following APIs which are accessible only to admins. * quotaTariffCreate * quotaTariffUpdate * createSecondaryStorageSelector * …

  • CVE-2025-59454MedNov 27, 2025
    risk 0.21cvss 4.3epss 0.00

    In Apache CloudStack, a gap in access control checks affected the APIs - createNetworkACL - listNetworkACLs - listResourceDetails - listVirtualMachinesUsageHistory - listVolumesUsageHistory While these APIs were accessible only to authorized users, insufficient permission…

  • CVE-2026-66721LowAug 21, 2026
    risk 0.18cvss 2.7epss 0.00

    Missing authorization issue for domain admins in CloudStack's host tags listing functionality. Domain Admins, by default, have permission to call the listHostTags API, but the API returns host tags for every host in the environment without domain scoping. It should instead…

  • CVE-2013-2758May 23, 2014
    risk 0.01cvss —epss 0.06

    Apache CloudStack 4.0.0 before 4.0.2 and Citrix CloudPlatform (formerly Citrix CloudStack) 3.0.x before 3.0.6 Patch C uses a hash of a predictable sequence, which makes it easier for remote attackers to guess the console access URL via a brute force attack.

  • CVE-2012-4501Oct 26, 2012
    risk 0.01cvss —epss 0.08

    Citrix Cloud.com CloudStack, and Apache CloudStack pre-release, allows remote attackers to make arbitrary API calls by leveraging the system user account, as demonstrated by API calls to delete VMs.

  • CVE-2014-9593Jan 15, 2015
    risk 0.00cvss —epss 0.03

    Apache CloudStack before 4.3.2 and 4.4.x before 4.4.2 allows remote attackers to obtain private keys via a listSslCerts API call.

  • CVE-2014-7807Dec 10, 2014
    risk 0.00cvss —epss 0.03

    Apache CloudStack 4.3.x before 4.3.2 and 4.4.x before 4.4.2 allows remote attackers to bypass authentication via a login request without a password, which triggers an unauthenticated bind.