Improper access control in Apache CloudStack - CVE-2025-22828
Published: February 28, 2025
Apache CloudStack
Detailed vulnerability description
The vulnerability allows a remote user to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to improper access restrictions. A remote user can guess resource UUIDs and read annotations on resources they are not allowed to access.
How to mitigate CVE-2025-22828
Cybersecurity Help is currently unaware of any official solution to address this vulnerability.
As a temporary solution the vendor recommends disabling listAnnotations and addAnnotation API access to non-admin roles.