Impact
Improper authorization checks enable a Domain Admin to create, update, delete, and list project roles and permissions for any project, regardless of its domain affiliation. This flaw permits a malicious admin to tamper with role definitions and permissions that should be confined to their own domain, effectively granting unauthorized influence over projects in unrelated domains. The weakness corresponds to improper authorization (CWE‑285).
Affected Systems
Vulnerable versions of Apache CloudStack range from 4.15.0.0 through 4.20.3.0 and from 4.21.0.0 through 4.22.1.0. The product is maintained by the Apache Software Foundation.
Risk and Exploitability
The EPSS score is 0.00132, indicating a very low exploitation probability, and the vulnerability is not listed in CISA’s KEV catalog, so public exploitation data is limited. The flaw requires valid Domain Admin credentials, meaning that an attacker must either compromise such an account or be a legitimate admin. Once authenticated, the attacker can manipulate any project role or permission, raising the risk of privilege escalation, data leakage, and denial of service for affected projects. Given the EPSS score of 0.00132 indicates a very low exploitation probability, the likelihood of exploitation remains low, but it cannot be fully discounted.
OpenCVE Enrichment