5 Essential Questions: How to Choose the best Managed Security Provider For your Business
August 8, 2024Choosing the Right VAPT Provider: A Guide for CISOs and Security Leaders
August 8, 20245 Essential Questions: How to Choose the best Managed Security Provider For your Business
August 8, 2024Choosing the Right VAPT Provider: A Guide for CISOs and Security Leaders
August 8, 2024Severity
High
Analysis Summary
CVE-2024-42062
Apache CloudStack could allow a remote attacker to obtain sensitive information, caused by improper access permission validation. By sending a specially crafted request, an attacker could exploit this vulnerability to obtain all registered account-users API and secret keys information, and use this information to launch further attacks against the affected system.
Impact
- Information Disclosure
Indicators of Compromise
CVE
- CVE-2024-42062
Affected Vendors
Affected Products
- Apache CloudStack 4.18.2.2
- Apache CloudStack 4.19.1.0
Remediation
Upgrade to the latest version of Apache CloudStack, available from the Apache Website.