Impact
Apache CloudStack’s LDAP authentication plugin allows any authenticated user with access to the listLdapConfigurations API to view LDAP provider configurations. The disclosed information includes sensitive configuration details such as server addresses, bind credentials, and user mappings. This exposure compromises the confidentiality of configuration data.
Affected Systems
The vulnerability affects Apache CloudStack versions from 4.2.0.0 through 4.20.3.0 and from 4.21.0.0 through 4.22.1.0. Users running any of these releases are potentially impacted.
Risk and Exploitability
The CVSS score for this vulnerability is 7.5, indicating a high severity. The EPSS score of < 1% suggests a low probability of exploitation at this time, and it is not listed in CISA’s KEV catalog. The attack requires only authentication with any role that has access to the listLdapConfigurations API, which by default is granted to all default roles. Therefore the likelihood of exploitation remains high in environments where default roles are not tightly controlled. Mitigation through an update to 4.20.3.1 or 4.22.1.1, or later releases, removes the flaw by restricting configuration disclosure.
OpenCVE Enrichment