Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
cloudstack vulnerabilities and exploits
(subscribe to this query)
NA
CVE-2024-29008
A problem has been identified in the CloudStack additional VM configuration (extraconfig) feature which can be misused by anyone who has privilege to deploy a VM instance or configure settings of an already deployed VM instance, to configure additional VM configuration even when ...
NA
CVE-2014-9593
Apache CloudStack prior to 4.3.2 and 4.4.x prior to 4.4.2 allows remote malicious users to obtain private keys via a listSslCerts API call.
Apache Cloudstack
Apache Cloudstack 4.4.1
Apache Cloudstack 4.4.0
NA
CVE-2014-7807
Apache CloudStack 4.3.x prior to 4.3.2 and 4.4.x prior to 4.4.2 allows remote malicious users to bypass authentication via a login request without a password, which triggers an unauthenticated bind.
Apache Cloudstack 4.3.0
Apache Cloudstack 4.3.1
Apache Cloudstack 4.4.0
Apache Cloudstack 4.4.1
NA
CVE-2013-2758
Apache CloudStack 4.0.0 prior to 4.0.2 and Citrix CloudPlatform (formerly Citrix CloudStack) 3.0.x prior to 3.0.6 Patch C uses a hash of a predictable sequence, which makes it easier for remote malicious users to guess the console access URL via a brute force attack.
Apache Cloudstack 4.0.2
Apache Cloudstack 4.0.1
Citrix Cloudplatform 3.0.3
Citrix Cloudplatform 3.0.5
Apache Cloudstack 4.0.0
Citrix Cloudplatform 3.0.6
Citrix Cloudplatform 3.0
Citrix Cloudplatform 3.0.4
NA
CVE-2013-2756
Apache CloudStack 4.0.0 prior to 4.0.2 and Citrix CloudPlatform (formerly Citrix CloudStack) 3.0.x prior to 3.0.6 Patch C allows remote malicious users to bypass the console proxy authentication by leveraging knowledge of the source code.
Apache Cloudstack 4.0.2
Apache Cloudstack 4.0.1
Citrix Cloudplatform 3.0.3
Citrix Cloudplatform 3.0.5
Apache Cloudstack 4.0.0
Citrix Cloudplatform 3.0.6
Citrix Cloudplatform 3.0
Citrix Cloudplatform 3.0.4
NA
CVE-2013-2757
Citrix CloudPlatform (formerly Citrix CloudStack) 3.0.x prior to 3.0.6 Patch C does not properly restrict access to VNC ports on the management network, which allows remote malicious users to have unspecified impact via unknown vectors.
Citrix Cloudplatform 3.0.6
Citrix Cloudplatform 3.0
Citrix Cloudplatform 3.0.5
Citrix Cloudplatform 3.0.3
Citrix Cloudplatform 3.0.4
NA
CVE-2014-0031
The (1) ListNetworkACL and (2) listNetworkACLLists APIs in Apache CloudStack prior to 4.2.1 allow remote authenticated users to list network ACLS for other users via a crafted request.
Apache Cloudstack 2.0
Apache Cloudstack 2.0.1
Apache Cloudstack 2.1.0
Apache Cloudstack 2.1.1
Apache Cloudstack 2.2.13
Apache Cloudstack 2.2.14
Apache Cloudstack 2.2.2
Apache Cloudstack 2.2.3
Apache Cloudstack
Apache Cloudstack 2.1.10
Apache Cloudstack 2.1.3
Apache Cloudstack 2.1.5
Apache Cloudstack 2.2.0
Apache Cloudstack 2.2.11
Apache Cloudstack 2.2.6
Apache Cloudstack 2.2.8
Apache Cloudstack 4.0.0
Apache Cloudstack 4.0.2
Apache Cloudstack 2.1.6
Apache Cloudstack 2.1.7
Apache Cloudstack 2.1.8
Apache Cloudstack 2.1.9
NA
CVE-2013-6398
The virtual router in Apache CloudStack prior to 4.2.1 does not preserve the source restrictions in firewall rules after being restarted, which allows remote malicious users to bypass intended restrictions via a request.
Apache Cloudstack 4.1.1
Apache Cloudstack 2.1.2
Apache Cloudstack 2.1.3
Apache Cloudstack 2.1.4
Apache Cloudstack 2.2.1
Apache Cloudstack 2.2.11
Apache Cloudstack 2.2.6
Apache Cloudstack 2.2.7
Apache Cloudstack 4.0.1
Apache Cloudstack 4.0.2
Apache Cloudstack 4.1.0
Apache Cloudstack
Apache Cloudstack 2.0
Apache Cloudstack 2.1.5
Apache Cloudstack 2.1.6
Apache Cloudstack 2.2.12
Apache Cloudstack 2.2.13
Apache Cloudstack 2.2.8
Apache Cloudstack 2.2.9
Apache Cloudstack 2.0.1
Apache Cloudstack 2.1.0
Apache Cloudstack 2.1.7
NA
CVE-2013-2136
Multiple cross-site scripting (XSS) vulnerabilities in Apache CloudStack prior to 4.1.1 allow remote malicious users to inject arbitrary web script or HTML via the (1) Physical network name to the Zone wizard; (2) New network name, (3) instance name, or (4) group to the Instance ...
Apache Cloudstack 2.0
Apache Cloudstack 2.0.1
Apache Cloudstack 2.1.5
Apache Cloudstack 2.1.6
Apache Cloudstack 2.2.12
Apache Cloudstack 2.2.13
Apache Cloudstack 2.2.9
Apache Cloudstack 3.0.0
Apache Cloudstack 2.1.10
Apache Cloudstack 2.1.2
Apache Cloudstack 2.1.9
Apache Cloudstack 2.2.0
Apache Cloudstack 2.2.3
Apache Cloudstack 2.2.5
Apache Cloudstack 2.2.6
Apache Cloudstack 4.0.0
Apache Cloudstack 4.0.1
Apache Cloudstack 2.1.0
Apache Cloudstack 2.1.1
Apache Cloudstack 2.1.7
Apache Cloudstack 2.1.8
Apache Cloudstack 2.2.14
NA
CVE-2012-5616
Apache CloudStack 4.0.0-incubating and Citrix CloudPlatform (formerly Citrix CloudStack) prior to 3.0.6 stores sensitive information in the log4j.conf log file, which allows local users to obtain (1) the SSH private key as recorded by the createSSHKeyPair API, (2) the password of...
Citrix Cloudplatform
Apache Cloudstack 4.0.0
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-4946
CVE-2024-30309
CVE-2024-4761
CVE-2024-30051
type confusion
memory leak
CVE-2024-30293
reflected XSS
CVE-2024-3126
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
NEXT »