CVE-2024-45693

Source
https://cve.org/CVERecord?id=CVE-2024-45693
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-45693.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2024-45693
Published
2024-10-16T07:52:25.816Z
Modified
2026-08-12T03:51:48.680222562Z
Severity
  • 8.0 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:N CVSS Calculator
Summary
Apache CloudStack: Request origin validation bypass makes account takeover possible
Details

Users logged into the Apache CloudStack's web interface can be tricked to submit malicious CSRF requests due to missing validation of the origin of the requests. This can allow an attacker to gain privileges and access to resources of the authenticated users and may lead to account takeover, disruption, exposure of sensitive data and compromise integrity of the resources owned by the user account that are managed by the platform.

This issue affects Apache CloudStack from 4.15.1.0 through 4.18.2.3 and 4.19.0.0 through 4.19.1.1

Users are recommended to upgrade to Apache CloudStack 4.18.2.4 or 4.19.1.2, or later, which addresses this issue.

Database specific
{
    "unresolved_ranges": [
        {
            "source": "AFFECTED_FIELD",
            "extracted_events": [
                {
                    "introduced": "4.15.1.0"
                },
                {
                    "last_affected": "4.18.2.3"
                },
                {
                    "introduced": "4.19.0.0"
                },
                {
                    "last_affected": "4.19.1.1"
                }
            ]
        },
        {
            "source": "DESCRIPTION",
            "extracted_events": [
                {
                    "introduced": "4.15.1.0"
                },
                {
                    "fixed": "4.18.2.3"
                },
                {
                    "introduced": "4.19.0.0"
                },
                {
                    "fixed": "4.19.1.1"
                }
            ]
        }
    ],
    "cwe_ids": [
        "CWE-352"
    ],
    "cna_assigner": "apache",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/45xxx/CVE-2024-45693.json"
}
References

Affected packages

Git / github.com/apache/cloudstack

Affected ranges

Type
GIT
Repo
https://github.com/apache/cloudstack
Events
Database specific
Show details
{
    "source": "CPE_RANGE",
    "cpe": "cpe:2.3:a:apache:cloudstack:*:*:*:*:*:*:*:*",
    "extracted_events": [
        {
            "introduced": "4.15.1.0"
        },
        {
            "fixed": "4.18.2.4"
        },
        {
            "introduced": "4.19.0.0"
        },
        {
            "fixed": "4.19.1.2"
        }
    ]
}

Affected versions

4.*
4.19.0.0
4.19.1.0
4.19.1.1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-45693.json"