Improper Access Logic in CloudStack Backup Plugin by Apache
CVE-2025-66171
6.5MEDIUM
What is CVE-2025-66171?
The CloudStack Backup Plugin versions 4.21.0.0 and 4.22.0.0 exhibit an improper access control vulnerability, allowing authenticated users to exploit specific APIs. This can lead to the creation of new virtual machines (VMs) utilizing the backups of any user within the CloudStack environment. Users of the Backup Plugin in CloudStack installations are advised to upgrade to version 4.22.0.1 to mitigate this security risk.
Affected Version(s)
Apache CloudStack 4.21.0.0 <= 4.22.0.0
References
CVSS V3.1
Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Fabricio Duarte <fabricio.duarte.jr@gmail.com>
Gabriel Ortiga Fernandes <gabriel.ortiga@hotmail.com>
Gabriel Pordeus Santos <gabrielpordeus@gmail.com>