Apache CloudStack has announced the release of critical security updates to address serious vulnerabilities in its KVM-based infrastructure. The latest LTS security releases, 4.18.2.5 and 4.19.1.3, patch a significant flaw that could potentially allow attackers to compromise KVM-based environments.
See also: Apache Roller CSRF vulnerability allows privilege escalation

The vulnerability, identified as CVE-2024-50386, affects Apache CloudStack versions 4.0.0 through 4.18.2.4 and 4.19.0.0 through 4.19.1.2. This security issue stems from the lack of validation checks for KVM-compatible templates during the template registration process.
Exploiting this flaw could allow attackers to deploy malicious instances, potentially gaining unauthorized access to host file systems and compromising the integrity, confidentiality, and availability of the KVM-based infrastructure managed by Apache CloudStack.
The severity of this vulnerability is rated as “Important”, with a CVSS v3.1 base score of 8.5 (High). This high score indicates the potential for significant impact on affected systems.
See also: Vulnerability in Apache Tomcat allows Dos attacks
To mitigate the risk, it is highly recommended that CloudStack administrators upgrade to the updated versions 4.18.2.5, 4.19.1.3 or later immediately. Users running versions older than 4.19.1.0 should skip the interim updates and upgrade directly to 4.19.1.3.

In addition to the upgrade, CloudStack has provided guidance to administrators to scan and validate existing templates compatible with KVM. This process involves executing specific commands on a primary file‑based storage space to identify potentially compromised disks.
The discovery of this bug in Apache CloudStack is credited to Kiran Chavala (kiranchavala@apache.org), highlighting the importance of community involvement in identifying and addressing security issues in open source projects.
This security update highlights the critical nature of promptly addressing vulnerabilities in cloud. It serves as a reminder for organizations using Apache CloudStack to maintain prudent security practices and keep their systems up to date with the latest security patches.
See also: Hackers attack Apache AXIS server
Security flaws are vulnerabilities in a system that attackers could potentially exploit to gain unauthorized access or cause damage. These flaws can arise from a variety of sources, including software bugs, improper configurations, or the use of outdated protocols. Identifying and addressing security flaws is critical to protecting sensitive data and maintaining system integrity. Regular updates, thorough code reviews, and the use of security best practices can help mitigate the risks associated with these vulnerabilities.
Source: cybersecuritynews
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
