Impact
The Apache CloudStack webhook module contains a Server‑Side Request Forgery flaw that allows an attacker to force the CloudStack instance to send HTTP requests to arbitrary URLs. This can expose internal services, leak sensitive data, or enable further lateral movement within the network. No evidence of privilege escalation or code execution has been presented; the primary impact is the ability to read or write to internal resources through outbound requests. Based on the description, it is inferred that exploiting the flaw requires the attacker to trigger a webhook delivery request, which typically demands access to the CloudStack API or the ability to configure webhook definitions.
Affected Systems
Apache CloudStack versions 4.20.0.0 through 4.20.3.0 and 4.21.0.0 through 4.22.1.0 are affected. Systems running any of these releases are vulnerable until they upgrade to 4.20.3.1, 4.22.1.1, or a later release that incorporates the fix.
Risk and Exploitability
The CVSS score of 9.1 indicates a high severity, and the EPSS score of < 1% suggests that, while the probability of an exploit occurring is low, the potential impact is significant. The vulnerability is not listed in the CISA KEV catalog, but because the attack requires only webhook delivery requests, it can be executed by any actor who can submit webhook payloads or activate existing webhook definitions. The SSRF weakness permits internal network enumeration and data exfiltration, making it a critical risk for environments where CloudStack APIs are exposed or where webhooks are not strictly controlled.
OpenCVE Enrichment