CVE-2025-59454: Apache CloudStack: Lack of user permission validation leading to data leak for few APIs
In Apache CloudStack, a gap in access control checks affected the APIs - createNetworkACL - listNetworkACLs - listResourceDetails - listVirtualMachinesUsageHistory - listVolumesUsageHistory
While these APIs were accessible only to authorized users, insufficient permission validation meant that users could occasionally access information beyond their intended scope.
Users are recommended to upgrade to Apache CloudStack 4.20.2.0 or 4.22.0.0, which fixes the issue.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-59454?
CVE-2025-59454 has a medium severity level due to the insufficient permission validation in specific Apache CloudStack APIs.
How do I fix CVE-2025-59454?
To fix CVE-2025-59454, update your Apache CloudStack installation to version 4.20.3.0 or later, or 4.22.1.0 or later.
What specific APIs are affected by CVE-2025-59454?
CVE-2025-59454 affects the APIs: createNetworkACL, listNetworkACLs, listResourceDetails, listVirtualMachinesUsageHistory, and listVolumesUsageHistory.
Who is affected by CVE-2025-59454?
Users of Apache CloudStack versions prior to 4.20.3.0 and 4.22.1.0 may be affected by CVE-2025-59454.
What type of vulnerability is CVE-2025-59454?
CVE-2025-59454 is an access control vulnerability that allows unauthorized actions through insufficient permission validation.