CVE-2024-45462: Apache CloudStack: Incomplete session invalidation on web interface logout
The logout operation in the CloudStack web interface does not expire the user session completely which is valid until expiry by time or restart of the backend service. An attacker that has access to a user's browser can use an unexpired session to gain access to resources owned by the logged out user account. This issue affects Apache CloudStack from 4.15.1.0 through 4.18.2.3; and from 4.19.0.0 through 4.19.1.1.
Users are recommended to upgrade to Apache CloudStack 4.18.2.4 or 4.19.1.2, or later, which addresses this issue.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-45462?
CVE-2024-45462 is considered a medium severity vulnerability due to the risk of session hijacking.
How do I fix CVE-2024-45462?
To fix CVE-2024-45462, upgrade to Apache CloudStack version 4.18.2.4 or 4.19.1.2 or later.
What causes CVE-2024-45462?
CVE-2024-45462 is caused by the logout operation in the CloudStack web interface not fully expiring user sessions.
Who is affected by CVE-2024-45462?
CVE-2024-45462 affects users of Apache CloudStack versions between 4.15.1.0 and 4.18.2.4, as well as versions between 4.19.0.0 and 4.19.1.2.
What can an attacker do with CVE-2024-45462?
An attacker with access to a user's browser can exploit an unexpired session to access sensitive resources.