Apache CloudStack Security Update Advisory
Overview
An update has been released to address vulnerabilities in Apache CloudStack. Users of the affected versions are advised to update to the latest version.
Affected Products
CVE-2024-45219
- CloudStack versions: 4.0.0 (inclusive) ~ 4.18.2.3 (inclusive)
- CloudStack versions: 4.19.0.0 (inclusive) ~ 4.19.1.1 (inclusive)
CVE-2024-45693, CVE-2024-45462
- CloudStack versions: 4.15.1.0 (inclusive) ~ 4.18.2.3 (inclusive)
- CloudStack versions: 4.19.0.0 (inclusive) ~ 4.19.1.1 (inclusive)
Resolved Vulnerabilities
Missing validation for KVM-compatible templates and volumes, which could allow an attacker to deploy a malicious instance or access the host file system, resulting in resource integrity, confidentiality breach, data loss, or denial of service (CVE-2024-45219)
Vulnerability in the web interface lacking validation of request origin, which could allow an attacker to hijack a user’s account or access resources via CSRF requests (CVE-2024-45693)
Sessions do not expire after logout, which could allow an attacker to access the resources of a logged out account if they gain access to the user’s browser (CVE-2024-45462)
Vulnerability Patches
Vulnerability patches have been made available in the latest update. Please follow the instructions on the Referenced Sites to update to the latest Vulnerability Patches version.
CVE-2024-45219, CVE-2024-45693, CVE-2024-45462
- CloudStack version: 4.18.2.4
- CloudStack version: 4.19.1.2
Referenced Sites
[1] CVE-2024-45219 Detail
https://nvd.nist.gov/vuln/detail/CVE-2024-45219
[2] CVE-2024-45693 Detail
https://nvd.nist.gov/vuln/detail/CVE-2024-45693
[3] CVE-2024-45462 Detail
https://nvd.nist.gov/vuln/detail/CVE-2024-45462
[4] [ADVISORY] Apache CloudStack LTS Security Releases 4.18.2.4 and 4.19.1.2
https://cloudstack.apache.org/blog/security-release-advisory-4.18.2.4-4.19.1.2/