Vulnerability record · CVE-2024-42222 · published 7 August 2024
CVE-2024-42222: Apache cloudstack information exposure vulnerability
Apache · Cloudstack
In Apache CloudStack 4.19.1.0, a regression in the network listing API allows unauthorised list access of network details for domain admin and normal user accounts. This vulnerability compromises tenant isolation, potentially leading to unauthorised access to network details, configurations and data. Affected users are advised to upgrade to version 4.19.1.1 to address this issue. Users on older versions of CloudStack considering to upgrade, can skip 4.19.1.0 and upgrade directly to 4.19.1.1.
Description
In Apache CloudStack 4.19.1.0, a regression in the network listing API allows unauthorised list access of network details for domain admin and normal user accounts. This vulnerability compromises tenant isolation, potentially leading to unauthorised access to network details, configurations and data. Affected users are advised to upgrade to version 4.19.1.1 to address this issue. Users on older versions of CloudStack considering to upgrade, can skip 4.19.1.0 and upgrade directly to 4.19.1.1.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://cloudstack.apache.org/blog/security-release-advisory-4.19.1.1-4.18.2.3 | Vendor Advisory |
| https://github.com/apache/cloudstack/issues/9456 | ExploitIssue TrackingThird Party Advisory |
| https://lists.apache.org/thread/lxqtfd6407prbw3801hb4fz3ot3t8wlj | Mailing ListVendor Advisory |
| https://www.shapeblue.com/shapeblue-security-advisory-apache-cloudstack-security-releases-4-18-2-3-and-4-19-1-1/ | Third Party Advisory |
| http://www.openwall.com/lists/oss-security/2024/08/06/6 |
Track CVE-2024-42222 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2024-42222), CISA KEV, FIRST EPSS (scores of 2026-09-29). This page is refreshed as NVD updates the record.