Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
apache cloudstack 4.1.0 vulnerabilities and exploits
(subscribe to this query)
4.3
CVSSv3
CVE-2013-4317
In Apache CloudStack 4.1.0 and 4.1.1, when calling the CloudStack API call listProjectAccounts as a regular, non-administrative user, the user is able to see information for accounts other than their own.
Apache Cloudstack 4.1.0
Apache Cloudstack 4.1.1
NA
CVE-2013-6398
The virtual router in Apache CloudStack prior to 4.2.1 does not preserve the source restrictions in firewall rules after being restarted, which allows remote malicious users to bypass intended restrictions via a request.
Apache Cloudstack 4.1.1
Apache Cloudstack 2.1.2
Apache Cloudstack 2.1.3
Apache Cloudstack 2.1.4
Apache Cloudstack 2.2.1
Apache Cloudstack 2.2.11
Apache Cloudstack 2.2.6
Apache Cloudstack 2.2.7
Apache Cloudstack 4.0.1
Apache Cloudstack 4.0.2
Apache Cloudstack 4.1.0
Apache Cloudstack
Apache Cloudstack 2.0
Apache Cloudstack 2.1.5
Apache Cloudstack 2.1.6
Apache Cloudstack 2.2.12
Apache Cloudstack 2.2.13
Apache Cloudstack 2.2.8
Apache Cloudstack 2.2.9
Apache Cloudstack 2.0.1
Apache Cloudstack 2.1.0
Apache Cloudstack 2.1.7
NA
CVE-2014-0031
The (1) ListNetworkACL and (2) listNetworkACLLists APIs in Apache CloudStack prior to 4.2.1 allow remote authenticated users to list network ACLS for other users via a crafted request.
Apache Cloudstack 2.0
Apache Cloudstack 2.0.1
Apache Cloudstack 2.1.0
Apache Cloudstack 2.1.1
Apache Cloudstack 2.2.13
Apache Cloudstack 2.2.14
Apache Cloudstack 2.2.2
Apache Cloudstack 2.2.3
Apache Cloudstack
Apache Cloudstack 2.1.10
Apache Cloudstack 2.1.3
Apache Cloudstack 2.1.5
Apache Cloudstack 2.2.0
Apache Cloudstack 2.2.11
Apache Cloudstack 2.2.6
Apache Cloudstack 2.2.8
Apache Cloudstack 4.0.0
Apache Cloudstack 4.0.2
Apache Cloudstack 2.1.6
Apache Cloudstack 2.1.7
Apache Cloudstack 2.1.8
Apache Cloudstack 2.1.9
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-32976
CVE-2024-33557
CVE-2024-36801
CVE-2024-35654
authentication bypass
CVE-2024-24919
CSRF
code execution
CVE-2024-27348
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started