Impact
Apache CloudStack users can access or delete sensitive webhook delivery information because an access control check is omitted in the API handling of listing and deleting deliveries. This flaw leads to exposure of confidential data and loss of data integrity for the deliveries stored by the platform.
Affected Systems
The vulnerability affects Apache CloudStack provided by the Apache Software Foundation. The affected variants include version series 4.20.x from 4.20.0.0 through 4.20.3.0 and 4.21.x through 4.22.1.0.
Risk and Exploitability
The CVSS score is 4.3 and the EPSS score is < 1%, so the severity assessment relies on the potential confidentiality impact and the widespread presence across several release lines. Based on the description, it is inferred that an attacker can exploit the vulnerability by interacting with the webhook delivery management APIs over the network. The KEV catalog does not list active exploitation, yet the existence of the flaw across multiple releases suggests a non‑negligible risk and warrants immediate attention.
OpenCVE Enrichment