By default the CloudStack management server honours the x-forwarded-for HTTP header and logs it as the source IP of an API request. This could lead to authentication bypass and other operational problems should an attacker decide to spoof their IP address this way. Users are recommended to upgrade to CloudStack version 4.18.1.1 or 4.19.0.1, which fixes this issue.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published: 2024-04-04T07:48:54.101Z

Updated: 2024-08-02T01:03:51.677Z

Reserved: 2024-03-13T22:56:41.313Z

Link: CVE-2024-29006

cve-icon Vulnrichment

Updated: 2024-08-02T01:03:51.677Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-04-04T08:15:06.810

Modified: 2024-04-04T12:48:41.700

Link: CVE-2024-29006

cve-icon Redhat

No data.