Skip to content

Releases: apache/cloudstack

Apache CloudStack 4.22.1.1 (LTS Security Release)

Choose a tag to compare

@shwstppr shwstppr released this 21 Aug 07:22

This is a security release that fixes the following on top of the 4.22.1.0 release:

CVE-2026-47359: OS Command Injection due to unsanitized mount command
CVE-2026-50112: RCE and SSRF in direct download, metalink and NFS templates
CVE-2026-50222: Improper access control in Userdata reference APIs
CVE-2026-59085: Server-Side Request Forgery (SSRF) vulnerability in webhook module
CVE-2026-59654: DoS caused by database connections leak
CVE-2026-59655: Unauthenticated OAuth provider client-secret disclosure
CVE-2026-59657: Sensitive Information Disclosure via Cleartext Storage in AsyncJob
CVE-2026-59780: LDAP provider configuration disclosure
CVE-2026-59799: Missing Privilege Check in Two-Factor Authentication Disable Flow
CVE-2026-61397: OAuth2 Token Cross-Request Leak
CVE-2026-61398: Cross-Site Scripting (XSS) Vulnerability in Instance Reset Password Function in UI
CVE-2026-61399: Cross-Site Scripting (XSS) Vulnerability in Lock User Function in UI
CVE-2026-61400: Get and Run Diagnostics Command Injection
CVE-2026-61422: Authenticated pre-validation SSRF in registerTemplate
CVE-2026-62440: Improper access control in Kubernetes Service (CKS) cluster manipulation
CVE-2026-65613: Webhook Deliveries Incorrect Access
CVE-2026-66721: Authorization issue with listHostTags for domain admins
CVE-2026-66722: ProjectRole & ProjectRolePermission authorization issue
CVE-2026-66797: Unauthorised comment creation and disclosure
CVE-2026-68745: SAML2 Signature Validation Silently Skipped for Cert-less IdP

Advisory: https://cloudstack.apache.org/blog/security-release-advisory-4.20.3.1-4.22.1.1/

Release notes: https://docs.cloudstack.apache.org/en/4.22.1.1/releasenotes
Installation docs: https://docs.cloudstack.apache.org/en/4.22.1.1/installguide
Upgrade docs: https://docs.cloudstack.apache.org/en/4.22.1.1/upgrading
Admin docs: https://docs.cloudstack.apache.org/en/4.22.1.1/adminguide
API docs: https://cloudstack.apache.org/api/apidocs-4.22

Apache CloudStack 4.20.3.1 (LTS Security Release)

Choose a tag to compare

@shwstppr shwstppr released this 21 Aug 07:17

This is a security release that fixes the following on top of the 4.20.3.1 release:

CVE-2026-47359: OS Command Injection due to unsanitized mount command
CVE-2026-50112: RCE and SSRF in direct download, metalink and NFS templates
CVE-2026-50222: Improper access control in Userdata reference APIs
CVE-2026-59085: Server-Side Request Forgery (SSRF) vulnerability in webhook module
CVE-2026-59654: DoS caused by database connections leak
CVE-2026-59655: Unauthenticated OAuth provider client-secret disclosure
CVE-2026-59657: Sensitive Information Disclosure via Cleartext Storage in AsyncJob
CVE-2026-59780: LDAP provider configuration disclosure
CVE-2026-59799: Missing Privilege Check in Two-Factor Authentication Disable Flow
CVE-2026-61397: OAuth2 Token Cross-Request Leak
CVE-2026-61398: Cross-Site Scripting (XSS) Vulnerability in Instance Reset Password Function in UI
CVE-2026-61399: Cross-Site Scripting (XSS) Vulnerability in Lock User Function in UI
CVE-2026-61400: Get and Run Diagnostics Command Injection
CVE-2026-61422: Authenticated pre-validation SSRF in registerTemplate
CVE-2026-65613: Webhook Deliveries Incorrect Access
CVE-2026-66721: Authorization issue with listHostTags for domain admins
CVE-2026-66722: ProjectRole & ProjectRolePermission authorization issue
CVE-2026-66797: Unauthorised comment creation and disclosure
CVE-2026-68745: SAML2 Signature Validation Silently Skipped for Cert-less IdP

Advisory: https://cloudstack.apache.org/blog/security-release-advisory-4.20.3.1-4.22.1.1/

Release notes: https://docs.cloudstack.apache.org/en/4.20.3.1/releasenotes
Installation docs: https://docs.cloudstack.apache.org/en/4.20.3.1/installguide
Upgrade docs: https://docs.cloudstack.apache.org/en/4.20.3.1/upgrading
Admin docs: https://docs.cloudstack.apache.org/en/4.20.3.1/adminguide
API docs: https://cloudstack.apache.org/api/apidocs-4.20

Apache CloudStack 4.22.1.0 (LTS)

Choose a tag to compare

@sureshanaparti sureshanaparti released this 26 May 13:33
348ce95

Apache CloudStack 4.22.0.1 (LTS Security Release)

Choose a tag to compare

@DaanHoogland DaanHoogland released this 08 May 13:12

This is a security release that fixes the following on top of the 4.22.0.1 release:

CVE-2025-66170 Any user can list backups that they should not have access to. (severity 'Low')
CVE-2025-66171 Any user can create a new VM from backups they should not have access to (severity 'Important')
CVE-2025-66172 Any user can attach a volume in their VMs from backups they should not have access to (severity 'Important')
CVE-2025-66467 MinIO policy remains intact on bucket deletion (severity 'Important')
CVE-2025-69233 Domain/account resources limits not honored (severity 'Moderate')
CVE-2026-25077 Unauthenticated Command Injection in Direct Download Templates (severity 'Important')
CVE-2026-25199 Proxmox Extension Allows Unauthorized Cross-Tenant Instance Access(severity 'Moderate')

Advisory: https://cloudstack.apache.org/blog/security-release-advisory-4.20.3.0-4.22.0.1/

Release notes: https://docs.cloudstack.apache.org/en/4.22.0.1/releasenotes
Installation docs: https://docs.cloudstack.apache.org/en/4.22.0.1/installguide
Upgrade docs: https://docs.cloudstack.apache.org/en/4.22.0.1/upgrading
Admin docs: https://docs.cloudstack.apache.org/en/4.22.0.1/adminguide
API docs: https://cloudstack.apache.org/api/apidocs-4.22

Apache CloudStack 4.20.3.0 (LTS)

Choose a tag to compare

@abh1sar abh1sar released this 17 Apr 08:12

Apache CloudStack 4.22.0.0 (LTS)

Choose a tag to compare

@harikrishna-patnala harikrishna-patnala released this 11 Nov 14:25

Apache CloudStack 4.20.2.0 (LTS)

Choose a tag to compare

@weizhouapache weizhouapache released this 27 Oct 08:34
4.20.2.0
4dc3931

Apache CloudStack 4.21.0.0 (Regular)

Choose a tag to compare

@sureshanaparti sureshanaparti released this 29 Aug 04:57
f9513b4

Apache CloudStack 4.20.1.0 (LTS)

Choose a tag to compare

@Pearl1594 Pearl1594 released this 10 Jun 14:51

Apache CloudStack 4.20 maintenance release

Release notes: https://docs.cloudstack.apache.org/en/4.20.1.0/releasenotes
Installation docs: https://docs.cloudstack.apache.org/en/4.20.1.0/installguide
Upgrade docs: https://docs.cloudstack.apache.org/en/4.20.1.0/upgrading
Admin docs: https://docs.cloudstack.apache.org/en/4.20.1.0/adminguide
API docs: https://cloudstack.apache.org/api/apidocs-4.20

This LTS release includes fixes for the following security issues:

  • CVE-2025-26521: CKS cluster in project exposes user API keys
  • CVE-2025-30675: Unauthorised template/ISO list access to the domain/resource admins
  • CVE-2025-47713: Domain Admin can reset Admin password in Root Domain
  • CVE-2025-47849: Insecure access of user's API/Secret Keys in the same domain
  • CVE-2025-22829: Unauthorised access to dedicated resources in Quota plugin

Advisory: https://cloudstack.apache.org/blog/cve-advisories-4.19.3.0-4.20.1.0

Apache CloudStack 4.19.3.0 (LTS)

Choose a tag to compare

@Pearl1594 Pearl1594 released this 10 Jun 14:50

Apache CloudStack 4.19 maintenance release

Release notes: https://docs.cloudstack.apache.org/en/4.19.3.0/releasenotes
Installation docs: https://docs.cloudstack.apache.org/en/4.19.3.0/installguide
Upgrade docs: https://docs.cloudstack.apache.org/en/4.19.3.0/upgrading
Admin docs: https://docs.cloudstack.apache.org/en/4.19.3.0/adminguide
API docs: https://cloudstack.apache.org/api/apidocs-4.19

This LTS release includes fixes for the following security issues:

  • CVE-2025-26521: CKS cluster in project exposes user API keys
  • CVE-2025-30675: Unauthorised template/ISO list access to the domain/resource admins
  • CVE-2025-47713: Domain Admin can reset Admin password in Root Domain
  • CVE-2025-47849: Insecure access of user's API/Secret Keys in the same domain

Advisory: https://cloudstack.apache.org/blog/cve-advisories-4.19.3.0-4.20.1.0