U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

Vulnerability Change Records for CVE-2024-42062

Change History

New CVE Received by NIST 8/07/2024 4:16:12 AM

Action Type Old Value New Value
Added CWE

								
							
							
						
Apache Software Foundation CWE-200
Added Description

								
							
							
						
CloudStack account-users by default use username and password based authentication for API and UI access. Account-users can generate and register randomised API and secret keys and use them for the purpose of API-based automation and integrations. Due to an access permission validation issue that affects Apache CloudStack versions 4.10.0 up to 4.19.1.0, domain admin accounts were found to be able to query all registered account-users API and secret keys in an environment, including that of a root admin. An attacker who has domain admin access can exploit this to gain root admin and other-account privileges and perform malicious operations that can result in compromise of resources integrity and confidentiality, data loss, denial of service and availability of CloudStack managed infrastructure.

Users are recommended to upgrade to Apache CloudStack 4.18.2.3 or 4.19.1.1, or later, which addresses this issue. Additionally, all account-user API and secret keys should be regenerated.
Added Reference

								
							
							
						
Apache Software Foundation https://cloudstack.apache.org/blog/security-release-advisory-4.19.1.1-4.18.2.3 [No types assigned]
Added Reference

								
							
							
						
Apache Software Foundation https://lists.apache.org/thread/lxqtfd6407prbw3801hb4fz3ot3t8wlj [No types assigned]
Added Reference

								
							
							
						
Apache Software Foundation https://www.shapeblue.com/shapeblue-security-advisory-apache-cloudstack-security-releases-4-18-2-3-and-4-19-1-1/ [No types assigned]