The CloudStack management server and secondary storage VM...
High severity
Unreviewed
Published
Apr 4, 2024
to the GitHub Advisory Database
•
Updated Nov 12, 2024
Description
Published by the National Vulnerability Database
Apr 4, 2024
Published to the GitHub Advisory Database
Apr 4, 2024
Last updated
Nov 12, 2024
The CloudStack management server and secondary storage VM could be tricked into making requests to restricted or random resources by means of following 301 HTTP redirects presented by external servers when downloading templates or ISOs. Users are recommended to upgrade to version 4.18.1.1 or 4.19.0.1, which fixes this issue.
References