https://seclists.org/oss-sec/2026/q2/459: CVE-2025-69233: Apache CloudStack: Domain/account sources limits not honod
Published May 8, 2026
·Updated
Affected Software
1 affected component
Apache CloudStack>=4.0.0<=4.20.2.0, >=4.21.0.0<=4.22.0.0
Frequently Asked Questions
1
What is the severity of CVE-2025-69233?
The severity of CVE-2025-69233 is classified as moderate.
2
Which versions of Apache CloudStack are affected by CVE-2025-69233?
CVE-2025-69233 affects Apache CloudStack versions from 4.0.0 to 4.22.0.0.
3
What is the nature of the vulnerability described in CVE-2025-69233?
CVE-2025-69233 involves time-of-check time-of-use race conditions and missing validations in the resource count logic.
4
How do I fix CVE-2025-69233?
To address CVE-2025-69233, upgrade to a fixed version of Apache CloudStack that resolves the identified vulnerabilities.
5
What can be the impact of CVE-2025-69233 on users?
The impact of CVE-2025-69233 may allow unauthorized resource count increments, potentially leading to resource exhaustion.