5 Essential Questions: How to Choose the best Managed Security Provider For your Business
August 8, 2024
Choosing the Right VAPT Provider: A Guide for CISOs and Security Leaders
August 8, 2024

CVE-2024-42062 – Apache CloudStack Vulnerability

Severity

High

Analysis Summary

CVE-2024-42062

Apache CloudStack could allow a remote attacker to obtain sensitive information, caused by improper access permission validation. By sending a specially crafted request, an attacker could exploit this vulnerability to obtain all registered account-users API and secret keys information, and use this information to launch further attacks against the affected system.

Impact

  • Information Disclosure

Indicators of Compromise

CVE

  • CVE-2024-42062

Affected Vendors

Apache

Affected Products

  • Apache CloudStack 4.18.2.2
  • Apache CloudStack 4.19.1.0

Remediation

Upgrade to the latest version of Apache CloudStack, available from the Apache Website.

Apache Website