CVE-2024-29006

Source
https://cve.org/CVERecord?id=CVE-2024-29006
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-29006.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2024-29006
Published
2024-04-04T07:48:54.101Z
Modified
2026-07-15T02:11:24.662851191Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
Apache CloudStack: x-forwarded-for HTTP header parsed by default
Details

By default the CloudStack management server honours the x-forwarded-for HTTP header and logs it as the source IP of an API request. This could lead to authentication bypass and other operational problems should an attacker decide to spoof their IP address this way. Users are recommended to upgrade to CloudStack version 4.18.1.1 or 4.19.0.1, which fixes this issue.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/29xxx/CVE-2024-29006.json",
    "cna_assigner": "apache",
    "unresolved_ranges": [
        {
            "source": "AFFECTED_FIELD",
            "extracted_events": [
                {
                    "introduced": "4.11.0.0"
                },
                {
                    "last_affected": "4.18.1.0"
                },
                {
                    "introduced": "4.19.0.0"
                },
                {
                    "last_affected": "4.19.0.0"
                }
            ]
        }
    ],
    "cwe_ids": [
        "CWE-290"
    ]
}
References

Affected packages

Git / github.com/apache/cloudstack

Affected ranges

Type
GIT
Repo
https://github.com/apache/cloudstack
Events
Database specific
{
    "cpe": [
        "cpe:2.3:a:apache:cloudstack:*:*:*:*:*:*:*:*",
        "cpe:2.3:a:apache:cloudstack:4.19.0.0:*:*:*:*:*:*:*"
    ],
    "source": [
        "CPE_RANGE",
        "CPE_STRING"
    ],
    "extracted_events": [
        {
            "introduced": "4.11.0.0"
        },
        {
            "fixed": "4.18.1.1"
        },
        {
            "introduced": "4.19.0.0"
        },
        {
            "last_affected": "4.19.0.0"
        }
    ]
}

Affected versions

4.*
4.19.0.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-29006.json"