Apache CloudStack Security Update Advisory

Overview

 

An update has been released to address vulnerabilities in Apache CloudStack. Users of the affected versions are advised to update to the latest version.

 

Affected Products

 

CVE-2024-45219

  • CloudStack versions: 4.0.0 (inclusive) ~ 4.18.2.3 (inclusive)
  • CloudStack versions: 4.19.0.0 (inclusive) ~ 4.19.1.1 (inclusive)

 

CVE-2024-45693, CVE-2024-45462

  • CloudStack versions: 4.15.1.0 (inclusive) ~ 4.18.2.3 (inclusive)
  • CloudStack versions: 4.19.0.0 (inclusive) ~ 4.19.1.1 (inclusive)

 

 

Resolved Vulnerabilities

 

Missing validation for KVM-compatible templates and volumes, which could allow an attacker to deploy a malicious instance or access the host file system, resulting in resource integrity, confidentiality breach, data loss, or denial of service (CVE-2024-45219)

Vulnerability in the web interface lacking validation of request origin, which could allow an attacker to hijack a user’s account or access resources via CSRF requests (CVE-2024-45693)

Sessions do not expire after logout, which could allow an attacker to access the resources of a logged out account if they gain access to the user’s browser (CVE-2024-45462)

 

Vulnerability Patches

 

Vulnerability patches have been made available in the latest update. Please follow the instructions on the Referenced Sites to update to the latest Vulnerability Patches version.

 

CVE-2024-45219, CVE-2024-45693, CVE-2024-45462

  • CloudStack version: 4.18.2.4
  • CloudStack version: 4.19.1.2

 

 

Referenced Sites

 

[1] CVE-2024-45219 Detail

https://nvd.nist.gov/vuln/detail/CVE-2024-45219

[2] CVE-2024-45693 Detail

https://nvd.nist.gov/vuln/detail/CVE-2024-45693

[3] CVE-2024-45462 Detail

https://nvd.nist.gov/vuln/detail/CVE-2024-45462

[4] [ADVISORY] Apache CloudStack LTS Security Releases 4.18.2.4 and 4.19.1.2

https://cloudstack.apache.org/blog/security-release-advisory-4.18.2.4-4.19.1.2/