Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Apache CloudStack — Vulnerabilities & Security Advisories 52

All 52 CVE vulnerabilities found in Apache CloudStack, with AI-generated Chinese analysis, references, and POCs.

This page aggregates known vulnerabilities associated with Apache CloudStack, a virtualization and cloud management platform. It collects publicly disclosed security flaws and their remediation details across multiple Common Weakness Enumerations (CWE) categories. Here, you can track the vendor's advisory history, analyze the prevalence of specific weakness classes, or review the full vulnerability timeline for this product. The dataset covers advisories published from 2014 through the present, offering a comprehensive view of how the software has evolved in terms of security posture. Use this resource to identify patterns in reported issues, assess risk exposure for deployments of Apache CloudStack, and understand the relationship between specific code defects and their real-world impact. The entries link to original sources, allowing direct verification of each record.

Vendor: Apache Software Foundation

CVE ID Title CVSS Severity Published
CVE-2025-22829 Apache CloudStack: Unauthorised access to dedicated resources in Quota plugin CWE-269 4.3AI Medium AI 2025-06-10
CVE-2025-26521 Apache CloudStack: CKS cluster in project exposes user API keys CWE-200 7.5AI High AI 2025-06-10
CVE-2025-47849 Apache CloudStack: Insecure access of user's API/Secret Keys in the same domain CWE-269 7.2AI High AI 2025-06-10
CVE-2025-47713 Apache CloudStack: Domain Admin can reset Admin password in Root Domain CWE-269 7.2AI High AI 2025-06-10
CVE-2025-22828 Apache CloudStack: Unauthorised access to annotations CWE-200 4.2 - 2025-01-13
CVE-2024-50386 Apache CloudStack: Directly downloaded templates can be used to abuse KVM-based infrastructure CWE-20 8.5 High 2024-11-12
CVE-2024-45219 Apache CloudStack: Uploaded and registered templates and volumes can be used to abuse KVM-based infrastructure CWE-20 8.5 High 2024-10-16
CVE-2024-45462 Apache CloudStack: Incomplete session invalidation on web interface logout CWE-613 6.3 Medium 2024-10-16
CVE-2024-45693 Apache CloudStack: Request origin validation bypass makes account takeover possible CWE-352 8.0 High 2024-10-16
CVE-2024-42062 Apache CloudStack: User Key Exposure to Domain Admins CWE-863 7.2AI High AI 2024-08-07
CVE-2024-42222 Apache CloudStack: Unauthorised Network List Access CWE-200 4.3AI Medium AI 2024-08-07
CVE-2024-41107 Apache CloudStack: SAML Signature Exclusion CWE-290 9.8 - 2024-07-19
CVE-2024-38346 Apache CloudStack: Unauthenticated cluster service port leads to remote execution CWE-94 10.0 - 2024-07-05
CVE-2024-39864 Apache CloudStack: Integration API service uses dynamic port when disabled CWE-665 9.1 - 2024-07-05
CVE-2024-29008 Apache CloudStack: The extraconfig feature can be abused to load hypervisor resources on a VM instance CWE-20 9.6 - 2024-04-04
CVE-2024-29007 Apache CloudStack: When downloading templates or ISOs, the management server and SSVM follow HTTP redirects with potentially dangerous consequences CWE-918 8.1 - 2024-04-04
CVE-2024-29006 Apache CloudStack: x-forwarded-for HTTP header parsed by default CWE-290 8.1 - 2024-04-04
CVE-2022-35741 Apache CloudStack SAML Single Sign-On XXE 9.8 - 2022-07-18
CVE-2022-26779 Apache Cloudstack insecure random number generation affects project email invitation 8.8 - 2022-03-15
CVE-2019-17562 Apache CloudStack baremetal组件输入验证错误漏洞 9.8 - 2020-05-14
CVE-2013-4317 Apache CloudStack 安全漏洞 6.5 - 2018-02-06
CVE-2016-6813 Apache CloudStack 安全漏洞 9.8 - 2018-02-06

All 52 known CVE vulnerabilities affecting Apache CloudStack with full Chinese analysis, references, and POCs where available.