Apache CloudStack是美国阿帕奇(Apache)基金会的一套基础架构即服务(IaaS)云计算平台。该平台主要用于部署和管理大型虚拟机网络。 Apache CloudStack 4.15.10到4.18.2.3版本和4.19.0.0到4.19.1.1版本存在代码问题漏洞,该漏洞源于用户登出后会话未完全失效,可能导致拥有用户浏览器访问权限的攻击者在会话过期前访问已登出用户账户的资源。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Apache Software Foundation | Apache CloudStack | 4.15.1.0 ~ 4.18.2.3 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2024-45219 | 8.5 HIGH | Apache CloudStack: Uploaded and registered templates and volumes can be used to abuse KVM- |
| CVE-2024-45693 | 8.0 HIGH | Apache CloudStack: Request origin validation bypass makes account takeover possible |
| CVE-2024-45461 | 5.7 MEDIUM | Apache CloudStack Quota plugin: Access checks not enforced in Quota |
| CVE-2024-45217 | Apache Solr: ConfigSets created during a backup restore command are trusted implicitly | |
| CVE-2024-45216 | Apache Solr: Authentication bypass possible using a fake URL Path ending |
No comments yet