VulnSea

cloudstack vulnerabilities

CVEs whose affected-version data names the cloudstack package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

5 CVEsRSS

CVE-2025-69233Medium· 6.5
4mo ago

Due to multiple time-of-check time-of-use race conditions in the resource count check and increment logic, as well as missing validations, users of the platform are able to exceed the allocation limits configured for their accounts/domai…

Due to multiple time-of-check time-of-use race conditions in the resource count check and increment logic, as well as missing validations, users of the platform are able to exceed the allocation limits configured for their accounts/domai…

▾ Sunlitapache · cloudstackEPSS 0.43%via NVD
CVE-2025-66467High· 8.0
4mo ago

Missing MinIO policy cleanup on bucket deletion via Apache CloudStack allows users to retain access to buckets which they previously owned

Missing MinIO policy cleanup on bucket deletion via Apache CloudStack allows users to retain access to buckets which they previously owned. If another user creates a new bucket with the same name, the previous owners can gain unauthorize…

▾ Twilightapache · cloudstackEPSS 0.37%via NVD
CVE-2025-66172High· 8.1
4mo ago

The CloudStack Backup plugin has an improper access logic in versions 4.21.0.0 and 4.22.0.0

The CloudStack Backup plugin has an improper access logic in versions 4.21.0.0 and 4.22.0.0. Anyone with authenticated user-account access in CloudStack 4.21.0.0+ environments, where this plugin is enabled and have access to specific API…

▾ Twilightapache · cloudstackEPSS 0.51%via NVD
CVE-2025-66171Medium· 6.5
4mo ago

The CloudStack Backup plugin has an improper access logic in versions 4.21.0.0 and 4.22.0.0

The CloudStack Backup plugin has an improper access logic in versions 4.21.0.0 and 4.22.0.0. Anyone with authenticated user-account access in CloudStack 4.21.0.0+ environments, where this plugin is enabled and have access to specific API…

▾ Sunlitapache · cloudstackEPSS 0.53%via NVD
CVE-2025-66170Medium· 6.5
4mo ago

The CloudStack Backup plugin has an improper authorization logic in versions 4.21.0.0 and 4.22.0.0

The CloudStack Backup plugin has an improper authorization logic in versions 4.21.0.0 and 4.22.0.0. Anyone with authenticated user-account access in CloudStack 4.21.0.0+ environments, where this plugin is enabled and has access to specif…

▾ Sunlitapache · cloudstackEPSS 0.49%via NVD
cloudstack vulnerabilities (CVEs) · VulnSea