Apache CloudStack是美国阿帕奇(Apache)基金会的一套基础架构即服务(IaaS)云计算平台。该平台主要用于部署和管理大型虚拟机网络。 Apache CloudStack 4.21.0.0版本至4.22.0.0版本存在信息泄露漏洞,该漏洞源于Proxmox扩展不当使用用户可编辑的实例设置proxmox_vmid,可能导致非特权攻击者修改设置引用其他租户的虚拟机,造成跨租户未授权访问。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Apache Software Foundation | Apache CloudStack | 4.21.0≤ 4.22.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Apache Software Foundation | Apache CloudStack | 4.21.0 ~ 4.22.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2025-66467 | 8.0 HIGH | Apache CloudStack: MinIO policy remains intact on bucket deletion |
| CVE-2025-69233 | 6.5 MEDIUM | Apache CloudStack: Domain/account resources limits not honored |
| CVE-2025-66170 | Apache CloudStack: Any user can list backups that they should not have access to | |
| CVE-2025-66171 | Apache CloudStack: Any user can create a new VM from backups they should not have access t | |
| CVE-2025-66172 | Apache CloudStack: Any user can attach a volume in their VMs from backups they should not | |
| CVE-2026-25077 | Apache CloudStack: Unauthenticated Command Injection in Direct Download Templates | |
| CVE-2026-39816 | Apache NiFi: Missing Execute Code Required Permission on TinkerpopClientService |
No comments yet