CyberRota Analysis
AI-GeneratedProxmox Virtual Environment versions 9.x prior to 9.1.8 and 8.x prior to 8.4.8 are vulnerable due to incorrect access control in the qemu-server, allowing users with limited privileges to retrieve hashed passwords through the cloudinit/dump API. This vulnerability could lead to unauthorized access and potential escalation of privileges within the environment. Organizations using affected versions should prioritize patching to mitigate the risk of credential exposure.
Original NVD Description
Incorrect access control in Proxmox Virtual Environment (PVE) 9.x qemu-server before 9.1.8 and 8.x before 8.4.8 allows users within limited privileges to obtain hashed passwords via the cloudinit/dump API.