PT-2022-3718 · Apache · Apache Cloudstack
V3Ged0Ge
·
Published
2022-07-18
·
Updated
2022-08-14
·
CVE-2022-35741
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Apache CloudStack versions 4.5.0 and later
Description
The issue is related to the SAML 2.0 authentication Service Provider plugin in Apache CloudStack, which is vulnerable to XML external entity (XXE) injection attacks. This plugin is not enabled by default, and an attacker would need to enable it to exploit the vulnerability. The SAML 2.0 messages constructed during the authentication flow are XML-based, and the XML data is parsed by standard libraries that are vulnerable to XXE injection attacks, potentially allowing arbitrary file reading, denial of service, and server-side request forgery (SSRF) on the CloudStack management server.
Recommendations
For Apache CloudStack versions 4.5.0 and later, consider disabling the SAML 2.0 authentication Service Provider plugin until a patch is available to prevent potential exploitation of XXE vulnerabilities. Restrict access to the SAML 2.0 plugin to minimize the risk of exploitation. Avoid using the SAML 2.0 plugin for authentication until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
XXE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apache Cloudstack