{
  "from_raw": "Abhishek Kumar <shwstppr@apache.org>",
  "from": "Abhishek Kumar <sh...@apache.org>",
  "gravatar": "044391215f1b1d4353e8d43ce314a054",
  "to": "an...@apache.org",
  "subject": "Re: [ADVISORY] Apache CloudStack LTS Security Releases 4.20.3.1 and 4.22.1.1",
  "message-id": "<CAM1si4X_AA2HQQromwiOaJWosWS5FZw_7xLY6Wxsm=yPhjPeOw@mail.gmail.com>",
  "mid": "dtw60nwhj93m43h5563l3l81pp05xcs1",
  "permalinks": [
    "dtw60nwhj93m43h5563l3l81pp05xcs1",
    "r041b79b135b899235cfeb8600f1993a85f93e636d46acffb13e4d38f@<announce.apache.org>"
  ],
  "dbid": "244d28d439cad4a67b3921e899608d703a731413d9c72c0896bc79c506eb3086",
  "cc": "",
  "epoch": 1787314102,
  "list": "<announce.apache.org>",
  "list_raw": "<announce.apache.org>",
  "date": "2026/08/21 12:08:22",
  "private": false,
  "references": "<CAM1si4VME85XuCyAFROMCBiCt7w_6Z2DK7U-_pD9z8gdgFtkhg@mail.gmail.com>",
  "in-reply-to": "<CAM1si4VME85XuCyAFROMCBiCt7w_6Z2DK7U-_pD9z8gdgFtkhg@mail.gmail.com>",
  "body": "The following security issue is also addressed in the LTS releases\n4.20.3.1 and 4.22.1.1, in addition to the issues already mentioned.\n\n- CVE-2026-59654 (severity 'Medium')\n\n# CVE-2026-59654: DoS caused by database connections leak\n\nMissing Release of Resource after Effective Lifetime vulnerability in\nApache CloudStack's scoped global configuration functionality. It\naffects different modules and plugins of the CloudStack management\nserver, including Quota, Host-HA, etc., and may lead to eventual\ndenial of service (DoS) scenario for the management server.\n\nCredits:\n - Henrique Sato <he...@gmail.com> (reporter)\n\nAffected versions:\n  - Apache CloudStack 4.7.0 through 4.20.3.0\n  - Apache CloudStack 4.21.0.0 through 4.22.1.0\n\nResolution:\nUsers are recommended to upgrade to versions 4.20.3.1 or 4.22.1.1 or\nlater, which\naddresses these issues.\n\nOn Fri, 21 Aug 2026 at 13:43, Abhishek Kumar <sh...@apache.org> wrote:\n>\n> The Apache CloudStack project announces the release of LTS releases\n> 4.20.3.1 and 4.22.1.1 that address the following security issues:\n>\n> - CVE-2026-47359 (severity 'Low')\n> - CVE-2026-50112 (severity 'Critical')\n> - CVE-2026-50222 (severity 'Important')\n> - CVE-2026-59085 (severity 'Moderate')\n> - CVE-2026-59655 (severity 'Moderate')\n> - CVE-2026-59657 (severity 'Low')\n> - CVE-2026-59780 (severity 'Low')\n> - CVE-2026-59799 (severity 'Important')\n> - CVE-2026-61397 (severity 'Critical')\n> - CVE-2026-61398 (severity 'Low')\n> - CVE-2026-61399 (severity 'Low')\n> - CVE-2026-61400 (severity 'Low')\n> - CVE-2026-61422 (severity 'Low')\n> - CVE-2026-62440 (severity 'Important')\n> - CVE-2026-65613 (severity 'Moderate')\n> - CVE-2026-66721 (severity 'Moderate')\n> - CVE-2026-66722 (severity 'Moderate')\n> - CVE-2026-66797 (severity 'Low')\n> - CVE-2026-68745 (severity 'Important')\n>\n>\n> # CVE-2026-47359: OS Command Injection due to unsanitized mount command\n>\n> Improper Neutralization of Special Elements used in an OS Command ('OS\n> Command Injection') vulnerability in Apache CloudStack's NAS backup\n> provider plugin. The addBackupRepository API (available since\n> 4.20.0.0) and updateBackupRepository API (introduced in 4.22.0.0)\n> accept unsanitized command options for the backup repository. A\n> malicious operator account can exploit this to inject arbitrary\n> commands that execute on the KVM hypervisor host when any account\n> subsequently performs a backup restore.\n>\n>\n> Credits:\n>  - \uae40\uc6b0\uc11d <wo...@gmail.com> (reporter)\n>  - \u0141ukasz Bawolski <Lu...@exea.pl> (reporter)\n>\n> Affected versions:\n>   - Apache CloudStack 4.20.0.0 through 4.20.3.0\n>   - Apache CloudStack 4.21.0.0 through 4.22.1.0\n>\n> Resolution:\n> Users are recommended to upgrade to versions 4.20.3.1 or 4.22.1.1 or\n> later, which addresses these issues.\n>\n>\n> # CVE-2026-50112: RCE and SSRF in direct download, metalink and NFS templates\n>\n> SSRF via Metalink Mirror URL Resolution:\n> An authenticated tenant can register a template pointing to an\n> attacker-controlled metalink file containing internal targets. The\n> Secondary Storage VM will retrieve the data and persist it as a\n> template file, which can later be downloaded through normal APIs.\n>\n> RCE on KVM hypervisor via NFS, Metalink files with/without Direct Downloads:\n> An authenticated CloudStack tenant holding the default User role can\n> execute arbitrary shell commands as root on the KVM hypervisor host\n> that runs other tenants' VMs. This is cross-tenant root on the\n> underlying compute, reachable via the public CloudStack API.\n>\n> When a User registers a VM template with directDownload=true and a URL\n> pointing to a .metalink file, the management server fetches the\n> metalink XML and dispatches download to the KVM agent. Inner URLs\n> inside the metalink XML are never re-validated against the scheme\n> allowlist.\n>\n> Credits:\n>  -  K (reporter)\n>  -  Samy Ghannad <sa...@samyghannad.com> (reporter)\n>  -  Katriel Moses <ka...@gmail.com> (reporter)\n>  -  Venkatraman Kumar <ve...@securin.io> (reporter)\n>  -  \u0141ukasz Bawolski <Lu...@exea.pl> (reporter)\n>\n> Affected versions:\n>   - Apache CloudStack 4.14.0.0 through 4.20.3.0\n>   - Apache CloudStack 4.21.0.0 through 4.22.1.0\n>\n> Resolution:\n> Users are recommended to upgrade to versions 4.20.3.1 or 4.22.1.1 or\n> later, which addresses these issues.\n>\n>\n> # CVE-2026-50222: Improper access control in Userdata reference APIs\n>\n> Missing Authorization, Exposure of Sensitive Information to an\n> Unauthorized Actor vulnerability in Apache CloudStack's Userdata\n> reference APIs.\n>\n> Several userdata-related APIs in Apache CloudStack, including\n> deleteUserData, linkUserDataToTemplate,\n> resetUserDataForVirtualMachine, deployVirtualMachine, and\n> updateVirtualMachine, exhibit missing or insufficient access control\n> validation, potentially allowing cross-tenant/cross-account access to\n> userdata resources that belong to other tenants.\n>\n> The deleteCniConfiguration API, introduced in 4.21.0.0, also exhibits\n> similar behaviour and lacks access validation.\n>\n> Credits:\n>  - Bernardo De Marco Gon\u00e7alves <be...@gmail.com> (reporter)\n>  - Yuliang Xiao <xy...@outlook.com> (reporter)\n>  - \u0141ukasz Bawolski <Lu...@exea.pl> (reporter)\n>  - George Chen (GitHub: geo-chen) (reporter)\n>  - KQ Wu <kq...@163.com> (reporter)\n>\n> Affected versions:\n>   - Apache CloudStack 4.18.0.0 through 4.20.3.0\n>   - Apache CloudStack 4.21.0.0 through 4.22.1.0\n>\n> Resolution:\n> Users are recommended to upgrade to versions 4.20.3.1 or 4.22.1.1 or\n> later, which addresses these issues.\n>\n>\n> # CVE-2026-59085: Server-Side Request Forgery (SSRF) vulnerability in\n> webhook module\n>\n> Server-Side Request Forgery (SSRF) vulnerability in Apache\n> CloudStack's webhook module, exploitable via webhook delivery\n> requests.\n>\n> Credits:\n>  - Jonathan Leitschuh <jo...@gmail.com> (reporter)\n>  - \u0141ukasz Bawolski <Lu...@exea.pl> (reporter)\n>  - George Chen (GitHub: geo-chen) (reporter)\n>\n> Affected versions:\n>   - Apache CloudStack 4.20.0.0 through 4.20.3.0\n>   - Apache CloudStack 4.21.0.0 through 4.22.1.0\n>\n> Resolution:\n> Users are recommended to upgrade to versions 4.20.3.1 or 4.22.1.1 or\n> later, which addresses these issues.\n>\n>\n>\n> #CVE-2026-59655: Unauthenticated OAuth provider client-secret disclosure\n>\n> Exposure of Sensitive Information to an Unauthorized Actor\n> vulnerability in Apache CloudStack's OAuth authentication plugin while\n> listing OAuth providers.\n>\n> Credits:\n>  - Yuliang Xiao <xy...@outlook.com> (reporter)\n>  - Stijn Simons <st...@portofantwerpbruges.com> (reporter)\n>\n> Affected versions;\n>   - Apache CloudStack 4.19.0.0 through 4.20.3.0\n>   - Apache CloudStack 4.21.0.0 through 4.22.1.0\n>\n> Resolution:\n> Users are recommended to upgrade to versions 4.20.3.1 or 4.22.1.1 or\n> later, which addresses these issues.\n>\n>\n>\n> # CVE-2026-59657: Sensitive Information Disclosure via Cleartext\n> Storage in AsyncJob\n>\n> Cleartext Storage of Sensitive Information vulnerability in Apache\n> CloudStack with AsyncJob storage in the database.\n>\n> Credits:\n>  - Davi Torres <da...@gmail.com> (reporter)\n>\n> Affected versions:\n>   - Apache CloudStack 4.0.0 through 4.20.3.0\n>   - Apache CloudStack 4.21.0.0 through 4.22.1.0\n>\n> Resolution:\n> Users are recommended to upgrade to versions 4.20.3.1 or 4.22.1.1 or\n> later, which addresses these issues.\n>\n>\n>\n> # CVE-2026-59780: LDAP provider configuration disclosure\n>\n> Exposure of Sensitive Information to an Unauthorized Actor\n> vulnerability in Apache CloudStack's LDAP authentication plugin while\n> listing LDAP providers.\n>\n> LDAP configurations can be listed by any authenticated user with access to\n> the listLdapConfigurations API. By default, this API is available to all\n> default roles.\n>\n> Credits:\n>  - \u0141ukasz Bawolski <Lu...@exea.pl> (reporter)\n>\n> Affected versions:\n>   - Apache CloudStack 4.2.0.0 through 4.20.3.0\n>   - Apache CloudStack 4.21.0.0 through 4.22.1.0\n>\n> Resolution:\n> Users are recommended to upgrade to versions 4.20.3.1 or 4.22.1.1 or\n> later, which addresses these issues.\n>\n>\n>\n> # CVE-2026-59799: Missing Privilege Check in Two-Factor Authentication\n> Disable Flow\n>\n> Improper Privilege Management vulnerability in Apache CloudStack's\n> Two-factor authentication plugin allowing bypass of the two-factor\n> authentication disable flow.\n>\n> Credits:\n>  - Erichen <ch...@ict.ac.cn> (reporter)\n>\n> Affected versions:\n>   - Apache CloudStack 4.18.0.0 through 4.20.3.0\n>   - Apache CloudStack 4.21.0.0 through 4.22.1.0\n>\n> Resolution:\n> Users are recommended to upgrade to versions 4.20.3.1 or 4.22.1.1 or\n> later, which addresses these issues.\n>\n>\n>\n> # CVE-2026-61397: OAuth2 Token Cross-Request Leak\n>\n> Exposure of Sensitive Information to an Unauthorized Actor\n> vulnerability in Apache CloudStack's OAuth2 authentication plugin and\n> Google OAuth integration.\n>\n> Credits:\n>  - Katriel Moses <ka...@gmail.com> (reporter)\n>  - \"Network and Cloud Laboratory (NaCl) KMITL\" <na...@kmitl.ac.th> (reporter)\n>  - Paratpanu Pechsaman <66...@kmitl.ac.th> (analyst)\n>  - Nutthawat Charoensiriphong <68...@kmitl.ac.th> (analyst)\n>  - Panabordee Panitchakit <68...@kmitl.ac.th> (analyst)\n>\n> Affected versions:\n>   - Apache CloudStack 4.19.0.0 through 4.20.3.0\n>   - Apache CloudStack 4.21.0.0 through 4.22.1.0\n>\n> Resolution:\n> Users are recommended to upgrade to versions 4.20.3.1 or 4.22.1.1 or\n> later, which addresses these issues.\n>\n>\n>\n> # CVE-2026-61398: Cross-Site Scripting (XSS) Vulnerability in Instance\n> Reset Password\n> Function in UI\n>\n> Improper Encoding or Escaping of Output vulnerability in Apache\n> CloudStack's UI while using Instance Reset Password functionality.\n>\n> Credits:\n>  - \u0141ukasz Bawolski <Lu...@exea.pl> (reporter)\n>\n> Affected versions:\n>   - Apache CloudStack 4.15.1.0 through 4.20.3.0\n>   - Apache CloudStack 4.21.0.0 through 4.22.1.0\n>\n> Resolution:\n> Users are recommended to upgrade to versions 4.20.3.1 or 4.22.1.1 or\n> later, which addresses these issues.\n>\n>\n>\n> # CVE-2026-61399: Cross-Site Scripting (XSS) Vulnerability in Lock\n> User Function in UI\n>\n> Improper Encoding or Escaping of Output vulnerability in Apache\n> CloudStack's UI while using Lock User Functionality.\n>\n> Credits:\n>  - \u0141ukasz Bawolski <Lu...@exea.pl> (reporter)\n>\n> Affected versions:\n>   - Apache CloudStack 4.20.0.0 through 4.20.3.0\n>   - Apache CloudStack 4.21.0.0 through 4.22.1.0\n>\n> Resolution:\n> Users are recommended to upgrade to versions 4.20.3.1 or 4.22.1.1 or\n> later, which addresses these issues.\n>\n>\n>\n> # CVE-2026-61400: Get and Run Diagnostics Command Injection\n>\n> Improper Neutralization of Special Elements used in a Command\n> ('Command Injection') vulnerability in Apache CloudStack's run and get\n> diagnostics functionality for the system VMs and virtual routers.\n>\n> An authenticated user holding the permissions required to invoke\n> either `getDiagnosticsData` or `runDiagnostics` can achieve arbitrary\n> command execution on the system VM and/or Virtual Router instances,\n> with commands running as root (or as the diagnostics-process user, at\n> minimum). This represents a full compromise of the affected instance\n> and, depending on network segmentation, may provide a foothold for\n> lateral movement within the CloudStack-managed infrastructure,\n> including access to guest network traffic handled by the compromised\n> Virtual Router.\n>\n> The getDiagnosticsData and runDiagnostics APIs are restricted to only\n> Admin role accounts by default.\n>\n> Credits:\n>  - \u0141ukasz Bawolski <Lu...@exea.pl> (reporter)\n>\n> Affected versions:\n>   - Apache CloudStack 4.14.0.0 through 4.20.3.0\n>   - Apache CloudStack 4.21.0.0 through 4.22.1.0\n>\n> Resolution:\n> Users are recommended to upgrade to versions 4.20.3.1 or 4.22.1.1 or\n> later, which addresses these issues.\n>\n>\n>\n> # CVE-2026-61422: Authenticated pre-validation SSRF in registerTemplate\n>\n> Authenticated pre-validation SSRF vulnerability in Apache CloudStack's\n> template and ISO registration functionality.\n>\n> When registering a template or ISO, CloudStack makes a live HTTP\n> HEAD/GET call to determine file size for secondary storage usage-limit\n> checks, and this happens before URL validation is performed. However,\n> this does not pose a malicious template or ISO registration risk, as\n> URL validation still occurs prior to the actual download by the\n> Secondary Storage VM.\n>\n> Credits:\n>  - Yuliang Xiao <xy...@outlook.com> (reporter)\n>\n> Affected versions:\n>   - Apache CloudStack 4.20.3.0\n>   - Apache CloudStack 4.21.0.0 through 4.22.1.0\n>\n> Resolution:\n> Users are recommended to upgrade to versions 4.20.3.1 or 4.22.1.1 or\n> later, which addresses these issues.\n>\n>\n>\n> # CVE-2026-62440: Improper access control in Kubernetes Service (CKS) cluster\n> manipulation\n>\n> Improper Access Control vulnerability in Apache CloudStack's\n> Kubernetes Service (CKS) plugin, allowing cross-tenant manipulation of\n> the Kubernetes cluster while adding and removing nodes.\n>\n> Credits:\n>  - George Chen (GitHub: geo-chen) (reporter)\n>  - D0HY30N (GitHub: D0HY30N) (reporter)\n>\n> Affected versions:\n>   - Apache CloudStack 4.21.0.0 through 4.22.1.0\n>\n> Resolution:\n> Users are recommended to upgrade to versions 4.22.1.1 or later, which\n> addresses these issues.\n>\n>\n>\n> # CVE-2026-65613: Webhook Deliveries Incorrect Access\n>\n> Exposure of Sensitive Information to an Unauthorized Actor\n> vulnerability in Apache CloudStack's Webhook module while listing and\n> deleting deliveries.\n>\n> Credits:\n>  - \u0141ukasz Bawolski <Lu...@exea.pl> (reporter)\n>\n> Affected versions:\n>   - Apache CloudStack 4.20.0.0 through 4.20.3.0\n>   - Apache CloudStack 4.21.0.0 through 4.22.1.0\n>\n> Resolution:\n> Users are recommended to upgrade to versions 4.20.3.1 or 4.22.1.1 or\n> later, which addresses these issues.\n>\n>\n>\n> # CVE-2026-66721: Authorization issue with listHostTags for domain admins\n>\n> Missing authorization issue for domain admins in CloudStack's host\n> tags listing functionality.\n>\n> Domain Admins, by default, have permission to call the listHostTags\n> API, but the API returns host tags for every host in the environment\n> without domain scoping. It should instead be restricted to only the\n> hosts dedicated to that admin's domain.\n>\n> Credits:\n>  - KQ Wu <kq...@163.com> (reporter)\n>\n> Affected versions:\n>   - Apache CloudStack 4.12.0.0 through 4.20.3.0\n>   - Apache CloudStack 4.21.0.0 through 4.22.1.0\n>\n> Resolution:\n> Users are recommended to upgrade to versions 4.20.3.1 or 4.22.1.1 or\n> later, which addresses these issues.\n>\n>\n>\n> # CVE-2026-66722: ProjectRole & ProjectRolePermission authorization issue\n>\n> Improper authorization for CRUD operations on Project Roles and\n> Project Role permissions for domain admins in CloudStack.\n>\n> A Domain Admin can create, update, delete, and list project roles and\n> project role permissions for projects in any domain, not just their\n> own. The check only confirms the caller is a Domain Admin, without\n> verifying whether the target project belongs to their domain or\n> subdomain. This allows a malicious Domain Admin to tamper with project\n> roles and permissions across unrelated domains.\n>\n> Credits:\n>  - KQ Wu <kq...@163.com> (reporter)\n>\n> Affected versions:\n>   - Apache CloudStack 4.15.0.0 through 4.20.3.0\n>   - Apache CloudStack 4.21.0.0 through 4.22.1.0\n>\n> Resolution:\n> Users are recommended to upgrade to versions 4.20.3.1 or 4.22.1.1 or\n> later, which addresses these issues.\n>\n>\n>\n> # CVE-2026-66797: Unauthorised comment creation and disclosure\n>\n> Improper access control in CloudStack's annotation functionality\n> allows unauthorized comment creation and disclosure.\n>\n> The addAnnotation and listAnnotation APIs perform an ownership check\n> when an entity's UUID is specified, but fail to honor its result\n> correctly. This lets any authenticated user write annotations to, and\n> disclose existing annotations/comments on, an entity they don't own by\n> simply supplying its UUID.\n>\n> Credits:\n>  - \u0141ukasz Bawolski <lu...@exea.pl> (reporter)\n>\n> Affected versions:\n>   - Apache CloudStack 4.16.0.0 through 4.20.3.0\n>   - Apache CloudStack 4.21.0.0 through 4.22.1.0\n>\n> Resolution:\n> Users are recommended to upgrade to versions 4.20.3.1 or 4.22.1.1 or\n> later, which addresses these issues.\n>\n>\n>\n> # CVE-2026-68745: SAML2 Signature Validation Silently Skipped for Cert-less IdP\n>\n> Certificate validation failures in SAML authentication in Apache\n> CloudStack 4.20.3.0 and 4.22.1.0 on all platforms allow a malicious\n> agent to forge a SAML response to the management server. The agent\n> will have to spoof the ip address of the IdP or get an url of its own\n> choosing registered in the management server, after which it can allow\n> logging on with forged signatures.\n>\n> Credits:\n>  -  Katriel Moses <ka...@gmail.com> (reporter)\n>\n> Affected versions:\n>   - Apache CloudStack 4.5.2 through 4.20.3.0\n>   - Apache CloudStack 4.21.0.0 through 4.22.1.0\n>\n> Resolution:\n> Users are recommended to upgrade to versions 4.20.3.1 or 4.22.1.1 or\n> later, which addresses these issues.\n>\n>\n> # Downloads and Documentation\n>\n> The official source code for the 4.20.3.1 and 4.22.1.1 releases can be\n> downloaded from the project downloads page:\n>\n> https://cloudstack.apache.org/downloads\n>\n> The 4.22.1.1 release notes can be found at:\n> - https://docs.cloudstack.apache.org/en/4.22.1.1/releasenotes/about.html\n>\n> In addition to the official source code release, individual\n> contributors have also made release packages available on the Apache\n> CloudStack download page, and available at:\n>\n> - https://download.cloudstack.org/el/8/\n> - https://download.cloudstack.org/el/9/\n> - https://download.cloudstack.org/el/10/\n> - https://download.cloudstack.org/suse/15/\n> - https://download.cloudstack.org/debian/dists/\n> - https://download.cloudstack.org/ubuntu/dists/\n> - https://www.shapeblue.com/cloudstack-packages/\n",
  "body_short": "The following security issue is also addressed in the LTS releases\n4.20.3.1 and 4.22.1.1, in addition to the issues already mentioned.\n\n- CVE-2026-59654 (severity 'Medium')\n\n# CVE-2026-59654: DoS cause",
  "html_source_only": false,
  "attachments": [],
  "forum": "announce@apache.org",
  "size": 21387,
  "id": "dtw60nwhj93m43h5563l3l81pp05xcs1"
}