{
  "from_raw": "Abhishek Kumar <shwstppr@apache.org>",
  "from": "Abhishek Kumar <sh...@apache.org>",
  "gravatar": "044391215f1b1d4353e8d43ce314a054",
  "to": "an...@apache.org",
  "subject": "[ADVISORY] Apache CloudStack LTS Security Releases 4.20.3.1 and 4.22.1.1",
  "message-id": "<CAM1si4VME85XuCyAFROMCBiCt7w_6Z2DK7U-_pD9z8gdgFtkhg@mail.gmail.com>",
  "mid": "4mlfxzkw97mh3n7vodpodsfff0xw991n",
  "permalinks": [
    "4mlfxzkw97mh3n7vodpodsfff0xw991n",
    "rd83cf22dc9a1d53abe2b58529d435d232a5ac79f67c98862c3ef3f2b@<announce.apache.org>"
  ],
  "dbid": "99ad817c561e6724952be68e59380d5b0fc61194e0545cf07434738fcf5ddc38",
  "cc": "",
  "epoch": 1787299995,
  "list": "<announce.apache.org>",
  "list_raw": "<announce.apache.org>",
  "date": "2026/08/21 08:13:15",
  "private": false,
  "references": "",
  "in-reply-to": "",
  "body": "The Apache CloudStack project announces the release of LTS releases\n4.20.3.1 and 4.22.1.1 that address the following security issues:\n\n- CVE-2026-47359 (severity 'Low')\n- CVE-2026-50112 (severity 'Critical')\n- CVE-2026-50222 (severity 'Important')\n- CVE-2026-59085 (severity 'Moderate')\n- CVE-2026-59655 (severity 'Moderate')\n- CVE-2026-59657 (severity 'Low')\n- CVE-2026-59780 (severity 'Low')\n- CVE-2026-59799 (severity 'Important')\n- CVE-2026-61397 (severity 'Critical')\n- CVE-2026-61398 (severity 'Low')\n- CVE-2026-61399 (severity 'Low')\n- CVE-2026-61400 (severity 'Low')\n- CVE-2026-61422 (severity 'Low')\n- CVE-2026-62440 (severity 'Important')\n- CVE-2026-65613 (severity 'Moderate')\n- CVE-2026-66721 (severity 'Moderate')\n- CVE-2026-66722 (severity 'Moderate')\n- CVE-2026-66797 (severity 'Low')\n- CVE-2026-68745 (severity 'Important')\n\n\n# CVE-2026-47359: OS Command Injection due to unsanitized mount command\n\nImproper Neutralization of Special Elements used in an OS Command ('OS\nCommand Injection') vulnerability in Apache CloudStack's NAS backup\nprovider plugin. The addBackupRepository API (available since\n4.20.0.0) and updateBackupRepository API (introduced in 4.22.0.0)\naccept unsanitized command options for the backup repository. A\nmalicious operator account can exploit this to inject arbitrary\ncommands that execute on the KVM hypervisor host when any account\nsubsequently performs a backup restore.\n\n\nCredits:\n - \uae40\uc6b0\uc11d <wo...@gmail.com> (reporter)\n - \u0141ukasz Bawolski <Lu...@exea.pl> (reporter)\n\nAffected versions:\n  - Apache CloudStack 4.20.0.0 through 4.20.3.0\n  - Apache CloudStack 4.21.0.0 through 4.22.1.0\n\nResolution:\nUsers are recommended to upgrade to versions 4.20.3.1 or 4.22.1.1 or\nlater, which addresses these issues.\n\n\n# CVE-2026-50112: RCE and SSRF in direct download, metalink and NFS templates\n\nSSRF via Metalink Mirror URL Resolution:\nAn authenticated tenant can register a template pointing to an\nattacker-controlled metalink file containing internal targets. The\nSecondary Storage VM will retrieve the data and persist it as a\ntemplate file, which can later be downloaded through normal APIs.\n\nRCE on KVM hypervisor via NFS, Metalink files with/without Direct Downloads:\nAn authenticated CloudStack tenant holding the default User role can\nexecute arbitrary shell commands as root on the KVM hypervisor host\nthat runs other tenants' VMs. This is cross-tenant root on the\nunderlying compute, reachable via the public CloudStack API.\n\nWhen a User registers a VM template with directDownload=true and a URL\npointing to a .metalink file, the management server fetches the\nmetalink XML and dispatches download to the KVM agent. Inner URLs\ninside the metalink XML are never re-validated against the scheme\nallowlist.\n\nCredits:\n -  K (reporter)\n -  Samy Ghannad <sa...@samyghannad.com> (reporter)\n -  Katriel Moses <ka...@gmail.com> (reporter)\n -  Venkatraman Kumar <ve...@securin.io> (reporter)\n -  \u0141ukasz Bawolski <Lu...@exea.pl> (reporter)\n\nAffected versions:\n  - Apache CloudStack 4.14.0.0 through 4.20.3.0\n  - Apache CloudStack 4.21.0.0 through 4.22.1.0\n\nResolution:\nUsers are recommended to upgrade to versions 4.20.3.1 or 4.22.1.1 or\nlater, which addresses these issues.\n\n\n# CVE-2026-50222: Improper access control in Userdata reference APIs\n\nMissing Authorization, Exposure of Sensitive Information to an\nUnauthorized Actor vulnerability in Apache CloudStack's Userdata\nreference APIs.\n\nSeveral userdata-related APIs in Apache CloudStack, including\ndeleteUserData, linkUserDataToTemplate,\nresetUserDataForVirtualMachine, deployVirtualMachine, and\nupdateVirtualMachine, exhibit missing or insufficient access control\nvalidation, potentially allowing cross-tenant/cross-account access to\nuserdata resources that belong to other tenants.\n\nThe deleteCniConfiguration API, introduced in 4.21.0.0, also exhibits\nsimilar behaviour and lacks access validation.\n\nCredits:\n - Bernardo De Marco Gon\u00e7alves <be...@gmail.com> (reporter)\n - Yuliang Xiao <xy...@outlook.com> (reporter)\n - \u0141ukasz Bawolski <Lu...@exea.pl> (reporter)\n - George Chen (GitHub: geo-chen) (reporter)\n - KQ Wu <kq...@163.com> (reporter)\n\nAffected versions:\n  - Apache CloudStack 4.18.0.0 through 4.20.3.0\n  - Apache CloudStack 4.21.0.0 through 4.22.1.0\n\nResolution:\nUsers are recommended to upgrade to versions 4.20.3.1 or 4.22.1.1 or\nlater, which addresses these issues.\n\n\n# CVE-2026-59085: Server-Side Request Forgery (SSRF) vulnerability in\nwebhook module\n\nServer-Side Request Forgery (SSRF) vulnerability in Apache\nCloudStack's webhook module, exploitable via webhook delivery\nrequests.\n\nCredits:\n - Jonathan Leitschuh <jo...@gmail.com> (reporter)\n - \u0141ukasz Bawolski <Lu...@exea.pl> (reporter)\n - George Chen (GitHub: geo-chen) (reporter)\n\nAffected versions:\n  - Apache CloudStack 4.20.0.0 through 4.20.3.0\n  - Apache CloudStack 4.21.0.0 through 4.22.1.0\n\nResolution:\nUsers are recommended to upgrade to versions 4.20.3.1 or 4.22.1.1 or\nlater, which addresses these issues.\n\n\n\n#CVE-2026-59655: Unauthenticated OAuth provider client-secret disclosure\n\nExposure of Sensitive Information to an Unauthorized Actor\nvulnerability in Apache CloudStack's OAuth authentication plugin while\nlisting OAuth providers.\n\nCredits:\n - Yuliang Xiao <xy...@outlook.com> (reporter)\n - Stijn Simons <st...@portofantwerpbruges.com> (reporter)\n\nAffected versions;\n  - Apache CloudStack 4.19.0.0 through 4.20.3.0\n  - Apache CloudStack 4.21.0.0 through 4.22.1.0\n\nResolution:\nUsers are recommended to upgrade to versions 4.20.3.1 or 4.22.1.1 or\nlater, which addresses these issues.\n\n\n\n# CVE-2026-59657: Sensitive Information Disclosure via Cleartext\nStorage in AsyncJob\n\nCleartext Storage of Sensitive Information vulnerability in Apache\nCloudStack with AsyncJob storage in the database.\n\nCredits:\n - Davi Torres <da...@gmail.com> (reporter)\n\nAffected versions:\n  - Apache CloudStack 4.0.0 through 4.20.3.0\n  - Apache CloudStack 4.21.0.0 through 4.22.1.0\n\nResolution:\nUsers are recommended to upgrade to versions 4.20.3.1 or 4.22.1.1 or\nlater, which addresses these issues.\n\n\n\n# CVE-2026-59780: LDAP provider configuration disclosure\n\nExposure of Sensitive Information to an Unauthorized Actor\nvulnerability in Apache CloudStack's LDAP authentication plugin while\nlisting LDAP providers.\n\nLDAP configurations can be listed by any authenticated user with access to\nthe listLdapConfigurations API. By default, this API is available to all\ndefault roles.\n\nCredits:\n - \u0141ukasz Bawolski <Lu...@exea.pl> (reporter)\n\nAffected versions:\n  - Apache CloudStack 4.2.0.0 through 4.20.3.0\n  - Apache CloudStack 4.21.0.0 through 4.22.1.0\n\nResolution:\nUsers are recommended to upgrade to versions 4.20.3.1 or 4.22.1.1 or\nlater, which addresses these issues.\n\n\n\n# CVE-2026-59799: Missing Privilege Check in Two-Factor Authentication\nDisable Flow\n\nImproper Privilege Management vulnerability in Apache CloudStack's\nTwo-factor authentication plugin allowing bypass of the two-factor\nauthentication disable flow.\n\nCredits:\n - Erichen <ch...@ict.ac.cn> (reporter)\n\nAffected versions:\n  - Apache CloudStack 4.18.0.0 through 4.20.3.0\n  - Apache CloudStack 4.21.0.0 through 4.22.1.0\n\nResolution:\nUsers are recommended to upgrade to versions 4.20.3.1 or 4.22.1.1 or\nlater, which addresses these issues.\n\n\n\n# CVE-2026-61397: OAuth2 Token Cross-Request Leak\n\nExposure of Sensitive Information to an Unauthorized Actor\nvulnerability in Apache CloudStack's OAuth2 authentication plugin and\nGoogle OAuth integration.\n\nCredits:\n - Katriel Moses <ka...@gmail.com> (reporter)\n - \"Network and Cloud Laboratory (NaCl) KMITL\" <na...@kmitl.ac.th> (reporter)\n - Paratpanu Pechsaman <66...@kmitl.ac.th> (analyst)\n - Nutthawat Charoensiriphong <68...@kmitl.ac.th> (analyst)\n - Panabordee Panitchakit <68...@kmitl.ac.th> (analyst)\n\nAffected versions:\n  - Apache CloudStack 4.19.0.0 through 4.20.3.0\n  - Apache CloudStack 4.21.0.0 through 4.22.1.0\n\nResolution:\nUsers are recommended to upgrade to versions 4.20.3.1 or 4.22.1.1 or\nlater, which addresses these issues.\n\n\n\n# CVE-2026-61398: Cross-Site Scripting (XSS) Vulnerability in Instance\nReset Password\nFunction in UI\n\nImproper Encoding or Escaping of Output vulnerability in Apache\nCloudStack's UI while using Instance Reset Password functionality.\n\nCredits:\n - \u0141ukasz Bawolski <Lu...@exea.pl> (reporter)\n\nAffected versions:\n  - Apache CloudStack 4.15.1.0 through 4.20.3.0\n  - Apache CloudStack 4.21.0.0 through 4.22.1.0\n\nResolution:\nUsers are recommended to upgrade to versions 4.20.3.1 or 4.22.1.1 or\nlater, which addresses these issues.\n\n\n\n# CVE-2026-61399: Cross-Site Scripting (XSS) Vulnerability in Lock\nUser Function in UI\n\nImproper Encoding or Escaping of Output vulnerability in Apache\nCloudStack's UI while using Lock User Functionality.\n\nCredits:\n - \u0141ukasz Bawolski <Lu...@exea.pl> (reporter)\n\nAffected versions:\n  - Apache CloudStack 4.20.0.0 through 4.20.3.0\n  - Apache CloudStack 4.21.0.0 through 4.22.1.0\n\nResolution:\nUsers are recommended to upgrade to versions 4.20.3.1 or 4.22.1.1 or\nlater, which addresses these issues.\n\n\n\n# CVE-2026-61400: Get and Run Diagnostics Command Injection\n\nImproper Neutralization of Special Elements used in a Command\n('Command Injection') vulnerability in Apache CloudStack's run and get\ndiagnostics functionality for the system VMs and virtual routers.\n\nAn authenticated user holding the permissions required to invoke\neither `getDiagnosticsData` or `runDiagnostics` can achieve arbitrary\ncommand execution on the system VM and/or Virtual Router instances,\nwith commands running as root (or as the diagnostics-process user, at\nminimum). This represents a full compromise of the affected instance\nand, depending on network segmentation, may provide a foothold for\nlateral movement within the CloudStack-managed infrastructure,\nincluding access to guest network traffic handled by the compromised\nVirtual Router.\n\nThe getDiagnosticsData and runDiagnostics APIs are restricted to only\nAdmin role accounts by default.\n\nCredits:\n - \u0141ukasz Bawolski <Lu...@exea.pl> (reporter)\n\nAffected versions:\n  - Apache CloudStack 4.14.0.0 through 4.20.3.0\n  - Apache CloudStack 4.21.0.0 through 4.22.1.0\n\nResolution:\nUsers are recommended to upgrade to versions 4.20.3.1 or 4.22.1.1 or\nlater, which addresses these issues.\n\n\n\n# CVE-2026-61422: Authenticated pre-validation SSRF in registerTemplate\n\nAuthenticated pre-validation SSRF vulnerability in Apache CloudStack's\ntemplate and ISO registration functionality.\n\nWhen registering a template or ISO, CloudStack makes a live HTTP\nHEAD/GET call to determine file size for secondary storage usage-limit\nchecks, and this happens before URL validation is performed. However,\nthis does not pose a malicious template or ISO registration risk, as\nURL validation still occurs prior to the actual download by the\nSecondary Storage VM.\n\nCredits:\n - Yuliang Xiao <xy...@outlook.com> (reporter)\n\nAffected versions:\n  - Apache CloudStack 4.20.3.0\n  - Apache CloudStack 4.21.0.0 through 4.22.1.0\n\nResolution:\nUsers are recommended to upgrade to versions 4.20.3.1 or 4.22.1.1 or\nlater, which addresses these issues.\n\n\n\n# CVE-2026-62440: Improper access control in Kubernetes Service (CKS) cluster\nmanipulation\n\nImproper Access Control vulnerability in Apache CloudStack's\nKubernetes Service (CKS) plugin, allowing cross-tenant manipulation of\nthe Kubernetes cluster while adding and removing nodes.\n\nCredits:\n - George Chen (GitHub: geo-chen) (reporter)\n - D0HY30N (GitHub: D0HY30N) (reporter)\n\nAffected versions:\n  - Apache CloudStack 4.21.0.0 through 4.22.1.0\n\nResolution:\nUsers are recommended to upgrade to versions 4.22.1.1 or later, which\naddresses these issues.\n\n\n\n# CVE-2026-65613: Webhook Deliveries Incorrect Access\n\nExposure of Sensitive Information to an Unauthorized Actor\nvulnerability in Apache CloudStack's Webhook module while listing and\ndeleting deliveries.\n\nCredits:\n - \u0141ukasz Bawolski <Lu...@exea.pl> (reporter)\n\nAffected versions:\n  - Apache CloudStack 4.20.0.0 through 4.20.3.0\n  - Apache CloudStack 4.21.0.0 through 4.22.1.0\n\nResolution:\nUsers are recommended to upgrade to versions 4.20.3.1 or 4.22.1.1 or\nlater, which addresses these issues.\n\n\n\n# CVE-2026-66721: Authorization issue with listHostTags for domain admins\n\nMissing authorization issue for domain admins in CloudStack's host\ntags listing functionality.\n\nDomain Admins, by default, have permission to call the listHostTags\nAPI, but the API returns host tags for every host in the environment\nwithout domain scoping. It should instead be restricted to only the\nhosts dedicated to that admin's domain.\n\nCredits:\n - KQ Wu <kq...@163.com> (reporter)\n\nAffected versions:\n  - Apache CloudStack 4.12.0.0 through 4.20.3.0\n  - Apache CloudStack 4.21.0.0 through 4.22.1.0\n\nResolution:\nUsers are recommended to upgrade to versions 4.20.3.1 or 4.22.1.1 or\nlater, which addresses these issues.\n\n\n\n# CVE-2026-66722: ProjectRole & ProjectRolePermission authorization issue\n\nImproper authorization for CRUD operations on Project Roles and\nProject Role permissions for domain admins in CloudStack.\n\nA Domain Admin can create, update, delete, and list project roles and\nproject role permissions for projects in any domain, not just their\nown. The check only confirms the caller is a Domain Admin, without\nverifying whether the target project belongs to their domain or\nsubdomain. This allows a malicious Domain Admin to tamper with project\nroles and permissions across unrelated domains.\n\nCredits:\n - KQ Wu <kq...@163.com> (reporter)\n\nAffected versions:\n  - Apache CloudStack 4.15.0.0 through 4.20.3.0\n  - Apache CloudStack 4.21.0.0 through 4.22.1.0\n\nResolution:\nUsers are recommended to upgrade to versions 4.20.3.1 or 4.22.1.1 or\nlater, which addresses these issues.\n\n\n\n# CVE-2026-66797: Unauthorised comment creation and disclosure\n\nImproper access control in CloudStack's annotation functionality\nallows unauthorized comment creation and disclosure.\n\nThe addAnnotation and listAnnotation APIs perform an ownership check\nwhen an entity's UUID is specified, but fail to honor its result\ncorrectly. This lets any authenticated user write annotations to, and\ndisclose existing annotations/comments on, an entity they don't own by\nsimply supplying its UUID.\n\nCredits:\n - \u0141ukasz Bawolski <lu...@exea.pl> (reporter)\n\nAffected versions:\n  - Apache CloudStack 4.16.0.0 through 4.20.3.0\n  - Apache CloudStack 4.21.0.0 through 4.22.1.0\n\nResolution:\nUsers are recommended to upgrade to versions 4.20.3.1 or 4.22.1.1 or\nlater, which addresses these issues.\n\n\n\n# CVE-2026-68745: SAML2 Signature Validation Silently Skipped for Cert-less IdP\n\nCertificate validation failures in SAML authentication in Apache\nCloudStack 4.20.3.0 and 4.22.1.0 on all platforms allow a malicious\nagent to forge a SAML response to the management server. The agent\nwill have to spoof the ip address of the IdP or get an url of its own\nchoosing registered in the management server, after which it can allow\nlogging on with forged signatures.\n\nCredits:\n -  Katriel Moses <ka...@gmail.com> (reporter)\n\nAffected versions:\n  - Apache CloudStack 4.5.2 through 4.20.3.0\n  - Apache CloudStack 4.21.0.0 through 4.22.1.0\n\nResolution:\nUsers are recommended to upgrade to versions 4.20.3.1 or 4.22.1.1 or\nlater, which addresses these issues.\n\n\n# Downloads and Documentation\n\nThe official source code for the 4.20.3.1 and 4.22.1.1 releases can be\ndownloaded from the project downloads page:\n\nhttps://cloudstack.apache.org/downloads\n\nThe 4.22.1.1 release notes can be found at:\n- https://docs.cloudstack.apache.org/en/4.22.1.1/releasenotes/about.html\n\nIn addition to the official source code release, individual\ncontributors have also made release packages available on the Apache\nCloudStack download page, and available at:\n\n- https://download.cloudstack.org/el/8/\n- https://download.cloudstack.org/el/9/\n- https://download.cloudstack.org/el/10/\n- https://download.cloudstack.org/suse/15/\n- https://download.cloudstack.org/debian/dists/\n- https://download.cloudstack.org/ubuntu/dists/\n- https://www.shapeblue.com/cloudstack-packages/\n",
  "body_short": "The Apache CloudStack project announces the release of LTS releases\n4.20.3.1 and 4.22.1.1 that address the following security issues:\n\n- CVE-2026-47359 (severity 'Low')\n- CVE-2026-50112 (severity 'Crit",
  "html_source_only": false,
  "attachments": [],
  "forum": "announce@apache.org",
  "size": 19335,
  "id": "4mlfxzkw97mh3n7vodpodsfff0xw991n"
}