CVE-2025-59454 | Teknoloji dünyasından en güncel haberleri ve güvenlikle ilgili gelişmeleri takip edin.

In Apache CloudStack, a gap in access control checks affected the APIs - createNetworkACL - listNetworkACLs - listResourceDetails - listVirtualMachinesUsageHist…
Medium CVSS: 4.3

CVE-2025-59454

In Apache CloudStack, a gap in access control checks affected the APIs - createNetworkACL
- listNetworkACLs
- listResourceDetails
- listVirtualMachinesUsageHistory
- listVolumesUsageHistory

While these APIs were accessible only to authorized users, insufficient permission validation meant that users could occasionally access information beyond their intended scope.




Users are recommended to upgrade to Apache CloudStack 4.20.2.0 or 4.22.0.0, which fixes the issue.
Vendor
Apache
Product
Cloudstack
CWE
CWE-200
Yayın Tarihi
2025-11-27 12:15:47
Güncelleme
2025-12-02 14:38:07
Source Identifier
security@apache.org
KEV Date Added
-

Kategoriler

Referanslar