CVE-2025-66172High· 8.1▾ TwilightThe CloudStack Backup plugin has an improper access logic in versions 4.21.0.0 and 4.22.0.0. Anyone with authenticated user-account access in CloudStack 4.21.0.0+ environments, where this plugin is enabled and have access to specific API…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 44.6 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.5%
The CloudStack Backup plugin has an improper access logic in versions 4.21.0.0 and 4.22.0.0. Anyone with authenticated user-account access in CloudStack 4.21.0.0+ environments, where this plugin is enabled and have access to specific APIs can restore a volume from any other user's backups and attach the volume to their own VMs.
Backup plugin users using CloudStack 4.21.0.0+ are recommended to upgrade to CloudStack version 4.22.0.1, which fixes this issue.
cloudstack >= 4.21.0.0, < 4.22.0.1Upgrade past the affected range:
cloudstack 4.22.0.1Connected by shared product, vendor, weakness, or advisory.
CVE-2025-66171Medium· 6.5The CloudStack Backup plugin has an improper access logic in versions 4.21.0.0 and 4.22.0.0
CVE-2025-69233Medium· 6.5Due to multiple time-of-check time-of-use race conditions in the resource count check and increment logic, as well as missing validations, users of the platform are able to exceed the allocation limits configured for their accounts/domai…
CVE-2025-66467High· 8.0Missing MinIO policy cleanup on bucket deletion via Apache CloudStack allows users to retain access to buckets which they previously owned
CVE-2025-66170Medium· 6.5The CloudStack Backup plugin has an improper authorization logic in versions 4.21.0.0 and 4.22.0.0
CVE-2025-53648Medium· 5.4SQL misconfiguration in the Gravitino UI, in versions 1.0.0 and below, can allow a malicious user to read or truncate files. Users are recommended to upgrade to version 1.0.0, which fixes this issue.
CVE-2025-49506High· 7.5APR-util versions 1.6.3 (and earlier) function apr_password_validate() was not constant-time with regards to hashes or passwords comparisons, potentially leaking their content via a side channel timing attack particularly on platforms wi…