PT-2025-4736 · Apache · Apache Cloudstack

Alex Perrakis

+1

·

Published

2025-01-13

·

Updated

2025-07-01

·

CVE-2025-22828

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
The software that is vulnerable is Apache CloudStack, specifically versions from 4.16.0 onwards. The vulnerability is an access validation issue that allows unauthorized access to annotations, which can lead to potential loss of confidentiality of CloudStack environments and resources if the comments contain privileged information. An attacker with a user account and access or prior knowledge of resource UUIDs can exploit this issue to read contents of the comments or add malicious comments to resources. However, guessing or brute-forcing resource UUIDs is generally hard to impossible, and access to listing or adding comments isn't the same as access to CloudStack resources, making this issue of very low severity and general low impact. There is no public exploit available for this vulnerability, and it is not known to have been exploited by attackers. CloudStack admins can disallow listAnnotations and addAnnotation API access to non-admin roles as an interim measure to address this issue.
#ApacheCloudStack #CVE202522828 #UnauthorisedAccess #Annotations #CloudSecurity #Vulnerability #LowSeverity #LowImpact

Fix

Information Disclosure

Weakness Enumeration

Related Identifiers

CVE-2025-22828

Affected Products

Apache Cloudstack