Advisories for Maven/Org.apache.cloudstack/Cloudstack package

2022

Improper Restriction of XML External Entity Reference

Apache CloudStack version 4.5.0 and later has a SAML 2.0 authentication Service Provider plugin which is found to be vulnerable to XML external entity (XXE) injection. This plugin is not enabled by default and the attacker would require that this plugin be enabled to exploit the vulnerability. When the SAML 2.0 plugin is enabled in affected versions of Apache CloudStack could potentially allow the exploitation of XXE vulnerabilities. The SAML …

Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)

Apache CloudStack prior to 4.16.1.0 used insecure random number generation for project invitation tokens. If a project invite is created based only on an email address, a random token is generated. An attacker with knowledge of the project ID and the fact that the invite is sent, could generate time deterministic tokens and brute force attempt to use them prior to the legitimate receiver accepting the invite. This feature is …

2020

Improper Input Validation

A buffer overflow vulnerability has been found in the baremetal component of Apache CloudStack. The vulnerability is due to the lack of validation of the mac parameter in baremetal virtual router. If you insert an arbitrary shell command into the mac parameter, v-router will process the command.

2018

Improper Authentication

Apache CloudStack to contain an API call designed to allow a user to register for the developer API. If a malicious user is able to determine the ID of another, non-root CloudStack user, the malicious user may be able to reset the API keys for the other user, in turn accessing their account and resources.