AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2025-22829

MEDIUM · CVSS 4.3 EPSS 0.69%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2025-06-10 · Last synced 2026-08-04

CyberRota Analysis

This is a medium severity vulnerability with a CVSS score of 4.3. Exploitation may require the attacker to be authenticated.

CVE
CVE-2025-22829
Severity
MEDIUM
CVSS
4.3
EPSS
0.69%

Original NVD Description

The CloudStack Quota plugin has an improper privilege management logic in version 4.20.0.0. Anyone with authenticated user-account access in CloudStack 4.20.0.0 environments, where this plugin is enabled and have access to specific APIs can enable or disable reception of quota-related emails for any account in the environment and list their configurations. Quota plugin users using CloudStack 4.20.0.0 are recommended to upgrade to CloudStack version 4.20.1.0, which fixes this issue.

Related CVEs

Other vulnerabilities affecting the same vendor(s)