Impact
A missing authorization check allows domain administrators to call the listHostTags API and retrieve tags for all hosts in the CloudStack environment, not just those belonging to their own domain. This flaw denies proper domain scoping and enables privileged users to view potentially sensitive configuration information about hosts they are not supposed to have visibility on. The vulnerability primarily leads to data exposure and can facilitate further compromise by providing an attacker with a broader view of the infrastructure.
Affected Systems
Apache CloudStack versions 4.12.0.0 through 4.20.3.0 and 4.21.0.0 through 4.22.1.0 are affected. The fix is included in versions 4.20.3.1 and 4.22.1.1 and later, so users should upgrade to at least those releases.
Risk and Exploitability
The CVSS score of 2.7 indicates a low overall severity, but the EPSS score remains < 1% and it is not in CISA KEV, so the exact exploitation probability is still unknown. Domain administrators have legitimate API access, so the attack vector is an authenticated API call. Given the possibility of exposing sensitive tags, the risk remains low to moderate. No specific exploit code is documented, but domain admins with ordinary privileges could exploit it.
OpenCVE Enrichment