Cyber Security News

Apache Cloudstack Vulnerability Exposes API & Secret Keys to Admin Accounts

The Apache CloudStack project has announced the release of long-term support (LTS) security updates, versions 4.18.2.3 and 4.19.1.1, which address two critical vulnerabilities, CVE-2024-42062 and CVE-2024-42222.

These vulnerabilities pose significant risks to the integrity, confidentiality, and availability of CloudStack-managed infrastructure.

CVE-2024-42062: User Key Exposure to Domain Admins

CVE-2024-42062 is a critical vulnerability that affects Apache CloudStack versions 4.10.0 up to 4.19.1.0. In these versions, domain admin accounts can query all registered account users’ API and secret keys, including those of root admins.

This flaw arises from an access permission validation issue, allowing domain admins to exploit this vulnerability to gain unauthorized privileges.

How to Build a Security Framework With Limited Resources IT Security Team (PDF) - Free Guide

An attacker with domain admin access can perform malicious operations, potentially compromising resources, causing data loss, and leading to denial of service.

Affected Version

Version RangeStatus
4.10.0 – 4.18.2.2Affected
4.19.0.0 – 4.19.1.0Affected

CVE-2024-42222: Unauthorized Network List Access

CVE-2024-42222 is another critical vulnerability found in Apache CloudStack version 4.19.1.0. This issue stems from a regression in the network listing API, allowing unauthorized access to network details for domain admin and normal user accounts.

This vulnerability undermines tenant isolation and can lead to unauthorized access to network configurations and data.

Affected Version

Version RangeStatus
4.19.1.0Affected

The Apache CloudStack project strongly recommends users upgrade to versions 4.18.2.3, 4.19.1.1, or later to mitigate these vulnerabilities.

Users older than 4.19.1.0 should skip version 4.19.1.0 and upgrade directly to 4.19.1.1. Additionally, users are advised to regenerate all existing user keys to maintain the security of their environments.

The vulnerabilities were reported by:

  • CVE-2024-42062: Fabricio Duarte
  • CVE-2024-42222: Christian Gross of Netcloud AG and Midhun Jose

These critical vulnerabilities highlight the importance of maintaining up-to-date software and promptly addressing security issues.

The Apache CloudStack project’s swift release of these updates underscores the community’s commitment to security and reliability. Users are urged to upgrade immediately to ensure the continued protection of their CloudStack environments.

Are you from SOC and DFIR Teams? – Analyse Malware Incidents & get live Access with ANY.RUN -> Free Access

Dhivya

Divya is a Senior Journalist at Cyber Security news covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.

Recent Posts

Hackers Target AI Infrastructure With RCE, Prompt Injection and API Key Theft

Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…

3 hours ago

Hackers Make Phishing Pages Change Their Code Every Time Someone Opens Them

Hackers are making some phishing pages harder to track by changing the code delivered to…

4 hours ago

Iran-Linked Hackers Reportedly Knock UK Power Plant Offline for Four Days

A cyber incident reportedly forced a British power plant to halt operations for about four…

5 hours ago

Russian Hackers Use New HOOKEDGE Malware to Spy on European Defense and Diplomatic Targets

Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…

5 hours ago

Ransomware Gang Claims AI Can Analyze 700GB of Stolen Data Every Hour

TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…

5 hours ago

Hackers Compromise Hundreds of WordPress Sites to Deploy Amatera Stealer via ClickFix

A fake student resume is being used to place a remote-access tool on researchers’ Windows…

7 hours ago