Severity
High
Analysis Summary
CVE-2024-42062
Apache CloudStack could allow a remote attacker to obtain sensitive information, caused by improper access permission validation. By sending a specially crafted request, an attacker could exploit this vulnerability to obtain all registered account-users API and secret keys information, and use this information to launch further attacks against the affected system.
Impact
- Information Disclosure
Indicators of Compromise
CVE
- CVE-2024-42062
Affected Vendors
Apache
Affected Products
- Apache CloudStack 4.18.2.2
- Apache CloudStack 4.19.1.0
Remediation
Upgrade to the latest version of Apache CloudStack, available from the Apache Website.


