EXECUTIVE SUMMARY:
Researchers have released long-term support security updates, versions 4.18.2.3 and 4.19.1.1, to address two critical vulnerabilities: CVE-2024-42062 and CVE-2024-42222. CVE-2024-42062 allows domain admins to access all registered account users' API and secret keys, including root admin keys, due to an access permission issue. CVE-2024-42222 permits unauthorized access to network details due to a regression in the network listing API, undermining tenant isolation. Users are advised to upgrade to the latest versions and regenerate all user keys to mitigate these risks.[/subscribe_to_unlock_form]
EXECUTIVE SUMMARY:
Researchers have released long-term support security updates, versions 4.18.2.3 and 4.19.1.1, to address two critical vulnerabilities: CVE-2024-42062 and CVE-2024-42222. CVE-2024-42062 allows domain admins to access all registered account users' API and secret keys, including root admin keys, due to an access permission issue. CVE-2024-42222 permits unauthorized access to network details due to a regression in the network listing API, undermining tenant isolation. Users are advised to upgrade to the latest versions and regenerate all user keys to mitigate these risks.[emaillocker id="1283"]
CVE-2024-42062: This vulnerability affects Apache CloudStack versions 4.10.0 through 4.19.1.0, allowing domain admins to query and access all registered users' API and secret keys, including those of root admins. The flaw results from improper access permission validation, leading to potential unauthorized privilege escalation, resource compromise, data loss, and denial of service.
CVE-2024-42222: Present in Apache CloudStack version 4.19.1.0, this vulnerability arises from a regression in the network listing API, which allows unauthorized access to network details for both domain admin and normal user accounts. This flaw threatens tenant isolation and can lead to unauthorized exposure of network configurations and data.
The Apache CloudStack project's swift release of these updates highlights the critical need to maintain up-to-date software and address vulnerabilities promptly. Users are urged to apply the updates and take necessary actions to ensure their environments remain secure.
RECOMMENDATION:
REFERENCES:
The following reports contain further technical details:
https://cybersecuritynews.com/apache-cloudstack-vulnerability/
[/emaillocker]