CVE-2024-29006
Last modified
CVE-2024-29006 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. By default the CloudStack management server honours the x-forwarded-for HTTP header and logs it as the source IP of an API request. This could lead to authentication bypass and other operational problems should an attacker decide to spoof their IP address this way. EPSS estimates a 0.87% chance of exploitation in the next 30 days.
Description
By default the CloudStack management server honours the x-forwarded-for HTTP header and logs it as the source IP of an API request. This could lead to authentication bypass and other operational problems should an attacker decide to spoof their IP address this way. Users are recommended to upgrade to CloudStack version 4.18.1.1 or 4.19.0.1, which fixes this issue.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Apache | Cloudstack | >= 4.11.0.0, < 4.18.1.1 |
| Apache | Cloudstack | 4.19.0.0 |
References
- https://lists.apache.org/thread/82f46pv7mvh95ybto5hn8wlo6g8jhjvpMailing List, Vendor Advisory
- https://lists.apache.org/thread/82f46pv7mvh95ybto5hn8wlo6g8jhjvpMailing List, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2024-29006?
How severe is CVE-2024-29006?
How do I fix CVE-2024-29006?
How Strix Helps
- Same Subject, Wrong User: A Cross-Issuer Account Takeover in n8nStrix found an identity-binding bug in n8n's token-exchange flow enabling account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-28999The SolarWinds Platform was determined to be affected by a R…7.5
- CVE-2024-2900A vulnerability, which was classified as critical, was found…8.8
- CVE-2024-29000The SolarWinds Platform was determined to be affected by a r…4.3
- CVE-2024-29001A SolarWinds Platform SWQL Injection Vulnerability was ident…7.4
- CVE-2024-29003The SolarWinds Platform was susceptible to a XSS vulnerabili…4.8
- CVE-2024-29004The SolarWinds Platform was determined to be affected by a s…4.3
- CVE-2024-29007The CloudStack management server and secondary storage VM co…7.3
- CVE-2024-29008A problem has been identified in the CloudStack additional V…6.4
- CVE-2024-29009Cross-site request forgery (CSRF) vulnerability in easy-popu…6.1
- CVE-2024-2901A vulnerability has been found in Tenda AC7 15.03.06.44 and …8.8
- CVE-2024-29010The XML document processed in the GMS ECM URL endpoint is vu…7.1
- CVE-2024-29011Use of hard-coded password in the GMS ECM endpoint leading t…7.5
Are you affected by CVE-2024-29006?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
