AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2024-45693

HIGH · CVSS 8 EPSS 0.51%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2024-10-16 · Last synced 2026-08-04

CyberRota Analysis

This is a high severity vulnerability with a CVSS score of 8.0. It affects Apache. Exploitation may require the attacker to be authenticated.

CVE
CVE-2024-45693
Severity
HIGH
CVSS
8
EPSS
0.51%
Apache

Original NVD Description

Users logged into the Apache CloudStack's web interface can be tricked to submit malicious CSRF requests due to missing validation of the origin of the requests. This can allow an attacker to gain privileges and access to resources of the authenticated users and may lead to account takeover, disruption, exposure of sensitive data and compromise integrity of the resources owned by the user account that are managed by the platform. This issue affects Apache CloudStack from 4.15.1.0 through 4.18.2.3 and 4.19.0.0 through 4.19.1.1 Users are recommended to upgrade to Apache CloudStack 4.18.2.4 or 4.19.1.2, or later, which addresses this issue.

Related CVEs

Other vulnerabilities affecting the same vendor(s)