CVE-2024-29008

Severity CVSS v4.0:
Pending analysis
Type:
CWE-20 Input Validation
Publication date:
04/04/2024
Last modified:
30/06/2025

Description

A problem has been identified in the CloudStack additional VM configuration (extraconfig) feature which can be misused by anyone who has privilege to deploy a VM instance or configure settings of an already deployed VM instance, to configure additional VM configuration even when the feature is not explicitly enabled by the administrator. In a KVM based CloudStack environment, an attacker can exploit this issue to attach host devices such as storage disks, and PCI and USB devices such as network adapters and GPUs, in a regular VM instance that can be further exploited to gain access to the underlying network and storage infrastructure resources, and access any VM instance disks on the local storage.<br /> <br /> Users are advised to upgrade to version 4.18.1.1 or 4.19.0.1, which fixes this issue.<br /> <br />

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:apache:cloudstack:*:*:*:*:*:*:*:* 4.14.0.0 (including) 4.18.1.1 (excluding)
cpe:2.3:a:apache:cloudstack:4.19.0.0:*:*:*:*:*:*:*