Impact
An unauthenticated user can retrieve OAuth client secrets by listing providers in Apache CloudStack, exposing sensitive information that could be used to compromise authentication flows. This flaw corresponds to CWE‑200 and enables an attacker to gain credentials that may lead to further exploitation.
Affected Systems
Apache Software Foundation’s Apache CloudStack versions from 4.19.0.0 through 4.20.3.0 and from 4.21.0.0 through 4.22.1.0 are vulnerable when the OAuth authentication plugin is enabled and the provider list endpoint is accessed without authentication.
Risk and Exploitability
The EPSS score is < 1% and the vulnerability is not listed in the CISA KEV catalog. The CVSS score is 7.5. The likely attack vector is an unauthenticated HTTP request to the provider listing API, which yields client secrets. While the flaw alone does not grant code execution, the disclosure of sensitive credentials is a significant confidentiality risk and could enable further attacks in the environment.
OpenCVE Enrichment