Releases: apache/cloudstack
Apache CloudStack 4.19.1.2 (LTS Security Release)
This is a security release that fixes the following on top of the 4.19.1.1 release:
- CVE-2024-45219: Uploaded and registered templates and volumes can be used to abuse KVM-based infrastructure
- CVE-2024-45461: Access checks not enforced in Quota
- CVE-2024-45462: Incomplete session invalidation on web interface logout
- CVE-2024-45693: Request origin validation bypass makes account takeover possible
Advisory: https://cloudstack.apache.org/blog/security-release-advisory-4.18.2.4-4.19.1.2
Release notes: https://docs.cloudstack.apache.org/en/4.19.1.2/releasenotes
Installation docs: https://docs.cloudstack.apache.org/en/4.19.1.2/installguide
Upgrade docs: https://docs.cloudstack.apache.org/en/4.19.1.2/upgrading
Admin docs: https://docs.cloudstack.apache.org/en/4.19.1.2/adminguide
API docs: https://cloudstack.apache.org/api/apidocs-4.19
Apache CloudStack 4.18.2.4 (LTS Security Release)
This is a security release that fixes the following on top of the 4.18.2.3 release:
- CVE-2024-45219: Uploaded and registered templates and volumes can be used to abuse KVM-based infrastructure
- CVE-2024-45461: Access checks not enforced in Quota
- CVE-2024-45462: Incomplete session invalidation on web interface logout
- CVE-2024-45693: Request origin validation bypass makes account takeover possible
Advisory: https://cloudstack.apache.org/blog/security-release-advisory-4.18.2.4-4.19.1.2
Release notes: https://docs.cloudstack.apache.org/en/4.18.2.4/releasenotes
Installation docs: https://docs.cloudstack.apache.org/en/4.18.2.4/installguide
Upgrade docs: https://docs.cloudstack.apache.org/en/4.18.2.4/upgrading
Admin docs: https://docs.cloudstack.apache.org/en/4.18.2.4/adminguide
API docs: https://cloudstack.apache.org/api/apidocs-4.18
Apache CloudStack 4.19.1.1 (LTS Security Release)
This is a security release that fixes the following on top of the 4.19.1.0 release:
- CVE-2024-42062: User Key Exposure to Domain Admins
- CVE-2024-42222: Unauthorised Network List Access
Advisory: https://cloudstack.apache.org/blog/security-release-advisory-4.19.1.1-4.18.2.3
Release notes: https://docs.cloudstack.apache.org/en/4.19.1.1/releasenotes
Installation docs: https://docs.cloudstack.apache.org/en/4.19.1.1/installguide
Upgrade docs: https://docs.cloudstack.apache.org/en/4.19.1.1/upgrading
Admin docs: https://docs.cloudstack.apache.org/en/4.19.1.1/adminguide
API docs: https://cloudstack.apache.org/api/apidocs-4.19
Apache CloudStack 4.18.2.3 (LTS Security Release)
This is a security release that fixes the following on top of the 4.18.2.2 security release:
- CVE-2024-42062: User Key Exposure to Domain Admins
Advisory: https://cloudstack.apache.org/blog/security-release-advisory-4.19.1.1-4.18.2.3
Release notes: https://docs.cloudstack.apache.org/en/4.18.2.3/releasenotes
Installation docs: https://docs.cloudstack.apache.org/en/4.18.2.3/installguide
Upgrade docs: https://docs.cloudstack.apache.org/en/4.18.2.3/upgrading
Admin docs: https://docs.cloudstack.apache.org/en/4.18.2.3/adminguide
API docs: https://cloudstack.apache.org/api/apidocs-4.18
Apache CloudStack 4.19.1.0 (LTS)
Apache CloudStack 4.19.1.0 (LTS) release
Release notes: https://docs.cloudstack.apache.org/en/4.19.1.0/releasenotes
Installation docs: https://docs.cloudstack.apache.org/en/4.19.1.0/installguide
Upgrade docs: https://docs.cloudstack.apache.org/en/4.19.1.0/upgrading
Admin docs: https://docs.cloudstack.apache.org/en/4.19.1.0/adminguide
API docs: https://cloudstack.apache.org/api/apidocs-4.19
Apache CloudStack 4.18.2.2 (LTS Security Release)
This is a security release that fixes the following on top of the 4.18.2.1 security release:
- CVE-2024-41107: SAML Signature Exclusion
Advisory: https://cloudstack.apache.org/blog/security-release-advisory-cve-2024-41107/
Release notes: https://docs.cloudstack.apache.org/en/4.18.2.2/releasenotes
Installation docs: https://docs.cloudstack.apache.org/en/4.18.2.2/installguide
Upgrade docs: https://docs.cloudstack.apache.org/en/4.18.2.2/upgrading
Admin docs: https://docs.cloudstack.apache.org/en/4.18.2.2/adminguide
API docs: https://cloudstack.apache.org/api/apidocs-4.18
Apache CloudStack 4.19.0.2 (LTS Security Release)
This is a security release that fixes the following on top of the 4.19.0.1 release:
- CVE-2024-38346: Unauthenticated cluster service port leads to remote execution
- CVE-2024-39864: Integration API service uses dynamic port when disabled
Advisory: https://cloudstack.apache.org/blog/security-release-advisory-4.19.0.2-4.18.2.1
Release notes: https://docs.cloudstack.apache.org/en/4.19.0.2/releasenotes
Installation docs: https://docs.cloudstack.apache.org/en/4.19.0.2/installguide
Upgrade docs: https://docs.cloudstack.apache.org/en/4.19.0.2/upgrading
Admin docs: https://docs.cloudstack.apache.org/en/4.19.0.2/adminguide
API docs: https://cloudstack.apache.org/api/apidocs-4.19
Apache CloudStack 4.18.2.1 (LTS Security Release)
This is a security release that fixes the following on top of the 4.18.2.0 release:
- CVE-2024-38346: Unauthenticated cluster service port leads to remote execution
- CVE-2024-39864: Integration API service uses dynamic port when disabled
Advisory: https://cloudstack.apache.org/blog/security-release-advisory-4.19.0.2-4.18.2.1
Release notes: https://docs.cloudstack.apache.org/en/4.18.2.1/releasenotes
Installation docs: https://docs.cloudstack.apache.org/en/4.18.2.1/installguide
Upgrade docs: https://docs.cloudstack.apache.org/en/4.18.2.1/upgrading
Admin docs: https://docs.cloudstack.apache.org/en/4.18.2.1/adminguide
API docs: https://cloudstack.apache.org/api/apidocs-4.18
Apache CloudStack 4.18.2.0 (LTS)
Release notes: https://docs.cloudstack.apache.org/en/4.18.2.0/releasenotes
Installation docs: https://docs.cloudstack.apache.org/en/4.18.2.0/installguide
Upgrade docs: https://docs.cloudstack.apache.org/en/4.18.2.0/upgrading
Admin docs: https://docs.cloudstack.apache.org/en/4.18.2.0/adminguide
API docs: https://cloudstack.apache.org/api/apidocs-4.18
Apache CloudStack 4.18.1.1 (LTS Security Release)
This is a security release the fixes the following on top of 4.18.1.0 release:
- CVE-2024-29006 x-forwarded-for parsed by default
- CVE-2024-29007 When downloading templates or ISOs, the UI/SSVM follow http redirects with potentially dangerous consequences
- CVE-2024-29008 The extraconfig feature can be abused to load hypervisor resources on a VM instance
Advisory: https://cloudstack.apache.org/blog/security-release-advisory-4.19.0.1-4.18.1.1