CVE-2012-4501: Critical severity Apache CloudStack vulnerability
Citrix Cloud.com CloudStack, and Apache CloudStack pre-release, allows remote attackers to make arbitrary API calls by leveraging the system user account, as demonstrated by API calls to delete VMs.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-4501?
CVE-2012-4501 is considered a high severity vulnerability due to the potential for remote attackers to execute arbitrary API calls.
How do I fix CVE-2012-4501?
To fix CVE-2012-4501, ensure that you update to the latest stable version of Citrix CloudStack or Apache CloudStack that addresses this vulnerability.
What systems are affected by CVE-2012-4501?
CVE-2012-4501 affects Citrix CloudStack and pre-release versions of Apache CloudStack.
What type of attacks can occur due to CVE-2012-4501?
CVE-2012-4501 allows remote attackers to execute arbitrary API commands, including the deletion of virtual machines.
Is there a workaround for CVE-2012-4501?
While the best solution is to upgrade, administrators can limit access to the affected APIs as a temporary workaround for CVE-2012-4501.