CyberRota Analysis
AI-GeneratedApache CloudStack is vulnerable due to a missing release of resources after their effective lifetime in its scoped global configuration, impacting various modules and plugins such as Quota and Host-HA. This flaw could lead to a denial of service (DoS) for the management server, potentially disrupting operations. Organizations using affected versions (4.7.0 through 4.20.3.0 and 4.21.0.0 through 4.22.1.0) should prioritize upgrading to at least version 4.20.3.1 or 4.22.1.1 to mitigate this risk.
Original NVD Description
Missing Release of Resource after Effective Lifetime vulnerability in Apache CloudStack's scoped global configuration functionality. It affects different modules and plugins of the CloudStack management server, including Quota, Host-HA, etc., and may lead to eventual denial of service (DoS) scenario for the management server. This issue affects Apache CloudStack: from 4.7.0 through 4.20.3.0 and from 4.21.0.0 through 4.22.1.0. Users are recommended to upgrade to version 4.20.3.1 or 4.22.1.1 or later, which fixes the issue.
Related CVEs
Other vulnerabilities affecting the same vendor(s)