← Back

CVE-2022-35741

nvd nist
Published: Jul 18, 2022Modified: Nov 21, 2024

JSON object

Loading...
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD

Description

Apache CloudStack version 4.5.0 and later has a SAML 2.0 authentication Service Provider plugin which is found to be vulnerable to XML external entity (XXE) injection. This plugin is not enabled by default and the attacker would require that this plugin be enabled to exploit the vulnerability. When the SAML 2.0 plugin is enabled in affected versions of Apache CloudStack could potentially allow the exploitation of XXE vulnerabilities. The SAML 2.0 messages constructed during the authentication flow in Apache CloudStack are XML-based and the XML data is parsed by various standard libraries that are now understood to be vulnerable to XXE injection attacks such as arbitrary file reading, possible denial of service, server-side request forgery (SSRF) on the CloudStack management server.

Affected (2)

Products: Apache: Cloudstack
1 product
Cloudstack
Configuration A
2 vulnerable
Vulnerable SoftwareAffected Versions
Apache
From 4.5.0 to 4.16.1.1
Version 4.17.0.0

References (6)

Source: security@apache.org
Mailing ListMitigationThird Party Advisory
Source: security@apache.org
Mailing ListMitigationThird Party Advisory
Source: security@apache.org
Issue TrackingMailing ListMitigationPatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListMitigationThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListMitigationThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingMailing ListMitigationPatchVendor Advisory

Timeline

No history available yet.