CVE-2024-29006

CRITICAL

Apache CloudStack 4.11.0.0-4.18.1.0 - Authentication Bypass via X-Forwarded-For Header Spoofing

Title source: llm
STIX 2.1

Description

By default the CloudStack management server honours the x-forwarded-for HTTP header and logs it as the source IP of an API request. This could lead to authentication bypass and other operational problems should an attacker decide to spoof their IP address this way. Users are recommended to upgrade to CloudStack version 4.18.1.1 or 4.19.0.1, which fixes this issue.

References (1)

Core 1
Core References
Mailing List, Vendor Advisory vendor-advisory
https://lists.apache.org/thread/82f46pv7mvh95ybto5hn8wlo6g8jhjvp

Scores

CVSS v3 9.8
EPSS 0.0087
EPSS Percentile 54.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-290
Status published
Products (2)
apache/cloudstack 4.19.0.0
apache/cloudstack 4.11.0.0 - 4.18.1.1
Published Apr 04, 2024
Tracked Since Feb 18, 2026