PT-2022-18079 · Apache · Apache Cloudstack
Jonathan Leitschuh
·
Published
2022-03-15
·
Updated
2022-03-22
·
CVE-2022-26779
CVSS v3.1
7.5
High
| Vector | AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Apache CloudStack versions prior to 4.16.1.0
Description
The issue arises from insecure random number generation for project invitation tokens. When a project invite is created based only on an email address, a random token is generated. An attacker with knowledge of the project ID and the fact that the invite is sent could generate time deterministic tokens and brute force attempt to use them prior to the legitimate receiver accepting the invite. This feature is not enabled by default, and the attacker would need to know or guess the project ID for the invite, in addition to the invitation token, and be an existing authorized user of CloudStack.
Recommendations
For versions prior to 4.16.1.0, update to version 4.16.1.0 or later to resolve the issue. As a temporary workaround, consider disabling the project invitation feature based on email addresses until a patch is available. Restrict access to project invitation tokens to minimize the risk of exploitation. Avoid using the project invitation feature for sensitive projects until the issue is resolved.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apache Cloudstack