Apache CloudStack是美国阿帕奇(Apache)基金会的一套基础架构即服务(IaaS)云计算平台。该平台主要用于部署和管理大型虚拟机网络。 Apache CloudStack 4.7.0到4.18.2.3版本和4.19.0.0到4.19.1.1版本存在安全漏洞,该漏洞源于缺少访问检查强制执行,非管理用户能够访问和修改与配额相关的配置和数据。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Apache Software Foundation | Apache CloudStack Quota plugin | 4.7.0 ~ 4.18.2.3 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2024-45219 | 8.5 HIGH | Apache CloudStack: Uploaded and registered templates and volumes can be used to abuse KVM- |
| CVE-2024-45693 | 8.0 HIGH | Apache CloudStack: Request origin validation bypass makes account takeover possible |
| CVE-2024-45462 | 6.3 MEDIUM | Apache CloudStack: Incomplete session invalidation on web interface logout |
| CVE-2024-45217 | Apache Solr: ConfigSets created during a backup restore command are trusted implicitly | |
| CVE-2024-45216 | Apache Solr: Authentication bypass possible using a fake URL Path ending |
No comments yet