Impact
Improper access control in Apache CloudStack’s annotation functionality allows an authenticated user to create and read comments on entities they do not own by supplying the target entity’s UUID to the addAnnotation and listAnnotation APIs. This flaw permits unauthorized data tampering and disclosure, allowing the attacker to manipulate or read annotations on an entity they do not own.
Affected Systems
The vulnerability affects Apache CloudStack installations using the annotation APIs, specifically versions 4.15.0.0 through 4.20.3.0 and 4.21.0.0 through 4.22.1.0. Any cluster or environment whose CloudStack components expose these endpoints to users could be impacted.
Risk and Exploitability
The CVSS score of 5.4 indicates a moderate severity vulnerability. The EPSS score of <1% and the fact that it is not listed in the CISA KEV catalog suggest that exploitation is currently rare, though the possibility remains. Attackers must have authenticated access to the CloudStack API and the UUID of a target entity; once satisfied, they can create annotations or read existing ones on an entity they do not own, leading to unauthorized data disclosure and potential manipulation of annotation data within the management plane.
OpenCVE Enrichment