PT-2022-18079 · Apache · Apache Cloudstack

Jonathan Leitschuh

·

Published

2022-03-15

·

Updated

2022-03-22

·

CVE-2022-26779

CVSS v3.1

7.5

High

VectorAV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Apache CloudStack versions prior to 4.16.1.0
Description The issue arises from insecure random number generation for project invitation tokens. When a project invite is created based only on an email address, a random token is generated. An attacker with knowledge of the project ID and the fact that the invite is sent could generate time deterministic tokens and brute force attempt to use them prior to the legitimate receiver accepting the invite. This feature is not enabled by default, and the attacker would need to know or guess the project ID for the invite, in addition to the invitation token, and be an existing authorized user of CloudStack.
Recommendations For versions prior to 4.16.1.0, update to version 4.16.1.0 or later to resolve the issue. As a temporary workaround, consider disabling the project invitation feature based on email addresses until a patch is available. Restrict access to project invitation tokens to minimize the risk of exploitation. Avoid using the project invitation feature for sensitive projects until the issue is resolved.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-26779
GHSA-VPCC-9RH2-8JFP

Affected Products

Apache Cloudstack