CyberRota Analysis
AI-GeneratedApache CloudStack is vulnerable to an authenticated pre-validation Server-Side Request Forgery (SSRF) during the template and ISO registration process, where live HTTP HEAD/GET calls are made before URL validation. While this does not allow for malicious template or ISO registration, it could potentially lead to unintended information disclosure or resource consumption. Organizations using affected versions (4.20.3.0, 4.21.0.0 to 4.22.1.0) should prioritize upgrading to versions 4.20.3.1 or 4.22.1.1 or later to mitigate this vulnerability.
Original NVD Description
Authenticated pre-validation SSRF vulnerability in Apache CloudStack's template and ISO registration functionality. When registering a template or ISO, CloudStack makes a live HTTP HEAD/GET call to determine file size for secondary storage usage-limit checks, and this happens before URL validation is performed. However, this does not pose a malicious template or ISO registration risk, as URL validation still occurs prior to the actual download by the Secondary Storage VM.This issue affects Apache CloudStack: in 4.20.3.0 and from 4.21.0.0 through 4.22.1.0. Users are recommended to upgrade to version 4.20.3.1 or 4.22.1.1 or later, which fixes the issue.
Related CVEs
Other vulnerabilities affecting the same vendor(s)