CVE-2024-29006
Apache CloudStack: x-forwarded-for HTTP header parsed by default
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
By default the CloudStack management server honours the x-forwarded-for HTTP header and logs it as the source IP of an API request. This could lead to authentication bypass and other operational problems should an attacker decide to spoof their IP address this way. Users are recommended to upgrade to CloudStack version 4.18.1.1 or 4.19.0.1, which fixes this issue.
De forma predeterminada, el servidor de administración de CloudStack respeta el encabezado HTTP x-forwarded-for y lo registra como la IP de origen de una solicitud de API. Esto podría provocar una omisión de autenticación y otros problemas operativos si un atacante decide falsificar su dirección IP de esta manera. Se recomienda a los usuarios actualizar a la versión 4.18.1.1 o 4.19.0.1 de CloudStack, que soluciona este problema.
CVSS Scores
SSVC
- Decision:Track
Timeline
- 2024-03-13 CVE Reserved
- 2024-04-04 CVE Published
- 2024-04-04 EPSS Updated
- 2024-08-02 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-290: Authentication Bypass by Spoofing
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://lists.apache.org/thread/82f46pv7mvh95ybto5hn8wlo6g8jhjvp | 2024-04-04 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Apache Software Foundation Search vendor "Apache Software Foundation" | Apache CloudStack Search vendor "Apache Software Foundation" for product "Apache CloudStack" | >= 4.11.0.0 <= 4.18.1.0 Search vendor "Apache Software Foundation" for product "Apache CloudStack" and version " >= 4.11.0.0 <= 4.18.1.0" | en |
Affected
| ||||||
Apache Software Foundation Search vendor "Apache Software Foundation" | Apache CloudStack Search vendor "Apache Software Foundation" for product "Apache CloudStack" | 4.19.0.0 Search vendor "Apache Software Foundation" for product "Apache CloudStack" and version "4.19.0.0" | en |
Affected
|