Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-29006


By default the CloudStack management server honours the x-forwarded-for HTTP header and logs it as the source IP of an API request. This could lead to authentication bypass and other operational problems should an attacker decide to spoof their IP address this way. Users are recommended to upgrade to CloudStack version 4.18.1.1 or 4.19.0.1, which fixes this issue.


Published

2024-04-04T08:15:06.810

Last Modified

2025-03-27T20:15:25.687

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 9.8 (CRITICAL)

Weaknesses
  • Type: Secondary
    CWE-290

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application apache cloudstack < 4.18.1.1 Yes
Application apache cloudstack 4.19.0.0 Yes

References