Apache CloudStack是美国阿帕奇(Apache)基金会的一套基础架构即服务(IaaS)云计算平台。该平台主要用于部署和管理大型虚拟机网络。 Apache CloudStack 4.15.1.0到4.18.2.3版本和4.19.0.0到4.19.1.1版本存在跨站请求伪造漏洞,该漏洞源于缺少对请求来源的验证,可能导致登录用户被诱导提交恶意CSRF请求,从而使攻击者获得特权并访问已认证用户的资源。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Apache Software Foundation | Apache CloudStack | 4.15.1.0 ~ 4.18.2.3 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2024-45219 | 8.5 HIGH | Apache CloudStack: Uploaded and registered templates and volumes can be used to abuse KVM- |
| CVE-2024-45462 | 6.3 MEDIUM | Apache CloudStack: Incomplete session invalidation on web interface logout |
| CVE-2024-45461 | 5.7 MEDIUM | Apache CloudStack Quota plugin: Access checks not enforced in Quota |
| CVE-2024-45217 | Apache Solr: ConfigSets created during a backup restore command are trusted implicitly | |
| CVE-2024-45216 | Apache Solr: Authentication bypass possible using a fake URL Path ending |
No comments yet