The Apache CloudStack project has announced the release of long-term support (LTS) security updates, versions 4.18.2.3 and 4.19.1.1, which address two critical vulnerabilities, CVE-2024-42062 and CVE-2024-42222.
These vulnerabilities pose significant risks to the integrity, confidentiality, and availability of CloudStack-managed infrastructure.
CVE-2024-42062 is a critical vulnerability that affects Apache CloudStack versions 4.10.0 up to 4.19.1.0. In these versions, domain admin accounts can query all registered account users’ API and secret keys, including those of root admins.
This flaw arises from an access permission validation issue, allowing domain admins to exploit this vulnerability to gain unauthorized privileges.
How to Build a Security Framework With Limited Resources IT Security Team (PDF) - Free Guide
An attacker with domain admin access can perform malicious operations, potentially compromising resources, causing data loss, and leading to denial of service.
Affected Version
| Version Range | Status |
| 4.10.0 – 4.18.2.2 | Affected |
| 4.19.0.0 – 4.19.1.0 | Affected |
CVE-2024-42222 is another critical vulnerability found in Apache CloudStack version 4.19.1.0. This issue stems from a regression in the network listing API, allowing unauthorized access to network details for domain admin and normal user accounts.
This vulnerability undermines tenant isolation and can lead to unauthorized access to network configurations and data.
Affected Version
| Version Range | Status |
| 4.19.1.0 | Affected |
The Apache CloudStack project strongly recommends users upgrade to versions 4.18.2.3, 4.19.1.1, or later to mitigate these vulnerabilities.
Users older than 4.19.1.0 should skip version 4.19.1.0 and upgrade directly to 4.19.1.1. Additionally, users are advised to regenerate all existing user keys to maintain the security of their environments.
The vulnerabilities were reported by:
These critical vulnerabilities highlight the importance of maintaining up-to-date software and promptly addressing security issues.
The Apache CloudStack project’s swift release of these updates underscores the community’s commitment to security and reliability. Users are urged to upgrade immediately to ensure the continued protection of their CloudStack environments.
Are you from SOC and DFIR Teams? – Analyse Malware Incidents & get live Access with ANY.RUN -> Free Access
Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…
Hackers are making some phishing pages harder to track by changing the code delivered to…
A cyber incident reportedly forced a British power plant to halt operations for about four…
Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…
TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…
A fake student resume is being used to place a remote-access tool on researchers’ Windows…