The Apache Software Foundation has warned about two serious security issues (CVE-2024-38346 and CVE-2024-39864) in Apache CloudStack, a popular open-source cloud computing platform. These vulnerabilities are a big threat to organizations using CloudStack to manage their virtualized infrastructure.
Unauthenticated Cluster Service Port (CVE-2024-38346)
By infosecbulletin
/ Monday , November 11 2024
On November 7, 2024, CISA released advisories about 3 critical security issues, vulnerabilities, and exploits related to Industrial Control Systems...
Read More
By infosecbulletin
/ Monday , November 11 2024
A cyberattack on an Israeli clearing company on Sunday left some people unable to use their credit cards for shopping...
Read More
By infosecbulletin
/ Monday , November 11 2024
Russia's media censor, Roskomnadzor, has blocked thousands of local websites using Cloudflare's encryption feature that enhances online privacy and security....
Read More
By infosecbulletin
/ Sunday , November 10 2024
Advertisement for selling the credentials of allegedly belonging to Indian government emails surfaced on the dark web marketplace. A hacker...
Read More
By infosecbulletin
/ Saturday , November 9 2024
Bangladesh faced a 105% rise in cyber incidents from the second to the third quarter of 2024, making it one...
Read More
By infosecbulletin
/ Friday , November 8 2024
The Socket Research Team has discovered a malicious package named "fabrice," pretending to be the legitimate fabric SSH automation library....
Read More
By infosecbulletin
/ Friday , November 8 2024
CISA has added a patched critical security flaw in Palo Alto Networks Expedition to its Known Exploited Vulnerabilities catalog due...
Read More
By infosecbulletin
/ Thursday , November 7 2024
Cisco has fixed a critical vulnerability, CVE-2024-20418, that allowed unauthenticated remote attackers to gain root access on Ultra-Reliable Wireless Backhaul...
Read More
By infosecbulletin
/ Wednesday , November 6 2024
In late October 2024, Cleafy’s Threat Intelligence team noticed a surge in a new Android malware known as TgToxic. However,...
Read More
By infosecbulletin
/ Wednesday , November 6 2024
Cyber Threat Intelligence Unit of BGD e-GOV CIRT found evidence of compromise linked to the vulnerability in F5 BIG-IP systems...
Read More
The vulnerability CVE-2024-38346 is found in the unauthenticated CloudStack cluster service port (default 9090). It can be exploited by attackers to run commands on hypervisors and CloudStack management servers. This could lead to full control over the CloudStack environment, causing data breaches, service disruptions, and financial losses.
Dynamic Port Assignment in Disabled Integration API Service (CVE-2024-39864)
The CVE-2024-39864 vulnerability affects the CloudStack integration API service. Although it should not be accessible when disabled, it mistakenly listens on a random port. Attackers who can access the CloudStack management network can find this port and use it to perform unauthorized administrative actions and execute remote code on CloudStack managed hosts. This vulnerability increases the risk of a complete infrastructure compromise.
Affected Versions and Urgent Call for Action
Apache CloudStack versions 4.0.0 to 4.18.2.0 and 4.19.0.0 to 4.19.0.1 have serious security flaws. The best way to fix this is to update to versions 4.18.2.1 or 4.19.0.2, which include patches to address these issues.
For organizations unable to upgrade immediately, the following temporary measures are advised:
Limit network access to the cluster service port (default 9090) on CloudStack management server hosts to only their peer management servers. Also, restrict network access on CloudStack management server hosts to only essential ports.