Impact
Apache CloudStack’s OAuth2 authentication plugin and Google OAuth integration contain an information disclosure flaw that can leak OAuth2 tokens across requests. Attackers who can read requests or responses may capture these tokens, potentially allowing them to impersonate users or gain unauthorized access to CloudStack resources. The weakness is a classic information disclosure (CWE‑200).
Affected Systems
The affected products are Apache CloudStack versions 4.19.0.0 through 4.20.3.0 and 4.21.0.0 through 4.22.1.0. Users are encouraged to upgrade to version 4.20.3.1 or 4.22.1.1 to resolve the issue.
Risk and Exploitability
The EPSS score is < 1%, indicating a low current public exploitation likelihood. The vulnerability is not listed in CISA’s KEV catalog, which confirms no known widespread exploitation. Because tokens are transmitted over network traffic, the potential for an attacker to intercept them exists if traffic is not properly secured. The CVSS score is 7.5, which indicates a high severity and demonstrates a significant risk to confidentiality and the potential for an unauthenticated or low‑privileged user to acquire sensitive authentication tokens. The likely attack vector is through application‑level manipulation of OAuth2 requests and responses, inferred from the description of cross‑request leakage.
OpenCVE Enrichment