CVE-2024-29007: Apache CloudStack: When downloading templates or ISOs, the management server and SSVM follow HTTP redirects with potentially dangerous consequences
The CloudStack management server and secondary storage VM could be tricked into making requests to restricted or random resources by means of following 301 HTTP redirects presented by external servers when downloading templates or ISOs. Users are recommended to upgrade to version 4.18.1.1 or 4.19.0.1, which fixes this issue.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-29007?
CVE-2024-29007 is considered to be a medium severity vulnerability due to potential unauthorized access to restricted resources.
How do I fix CVE-2024-29007?
To fix CVE-2024-29007, users should upgrade to Apache CloudStack version 4.19.1 or later.
Which versions of Apache CloudStack are affected by CVE-2024-29007?
CVE-2024-29007 affects Apache CloudStack versions up to 4.18.1 and 4.19.0.
What type of vulnerability is CVE-2024-29007?
CVE-2024-29007 is a security vulnerability that allows for possible unauthorized requests due to improper handling of HTTP redirects.
Who should be concerned about CVE-2024-29007?
Administrators and users of Apache CloudStack versions prior to 4.19.1 should be concerned about CVE-2024-29007.