« Volver al listado

CVE-2024-45693

Estado: ModificadaAlta (8.8)—

Users logged into the Apache CloudStack's web interface can be tricked to submit malicious CSRF requests due to missing validation of the origin of the requests. This can allow an attacker to gain privileges and access to resources of the authenticated users and may lead to account takeover, disruption, exposure of sensitive data and compromise integrity of the resources owned by the user account that are managed by the platform.

This issue affects Apache CloudStack from 4.15.1.0 through 4.18.2.3 and 4.19.0.0 through 4.19.1.1

Users are recommended to upgrade to Apache CloudStack 4.18.2.4 or 4.19.1.2, or later, which addresses this issue.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

CSRF en interfaz web (CWE-352) sin validación de origen requiere interacción del usuario (UI:R) autenticado. El ataque usa ingeniería social (XSS-like) contra sesiones válidas, no ejecución de código en cliente local.

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2024-45693",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2024-45693",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2024-10-16T14:55:50.101049Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "security@apache.org",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 8,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:N",
          "integrityImpact": "HIGH",
          "userInteraction": "REQUIRED",
          "attackComplexity": "HIGH",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.8,
        "exploitabilityScore": 1.6
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 8.8,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "security@apache.org",
      "affectedData": [
        {
          "vendor": "Apache Software Foundation",
          "product": "Apache CloudStack",
          "versions": [
            {
              "status": "affected",
              "version": "4.15.1.0",
              "versionType": "semver",
              "lessThanOrEqual": "4.18.2.3"
            },
            {
              "status": "affected",
              "version": "4.19.0.0",
              "versionType": "semver",
              "lessThanOrEqual": "4.19.1.1"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    },
    {
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
      "affectedData": [
        {
          "cpes": [
            "cpe:2.3:a:apache:cloudstack:*:*:*:*:*:*:*:*"
          ],
          "vendor": "apache",
          "product": "cloudstack",
          "versions": [
            {
              "status": "affected",
              "version": "4.15.1.0",
              "versionType": "semver",
              "lessThanOrEqual": "4.18.2.3"
            },
            {
              "status": "affected",
              "version": "4.19.0.0",
              "versionType": "semver",
              "lessThanOrEqual": "4.19.1.1"
            }
          ],
          "defaultStatus": "unknown"
        }
      ]
    }
  ],
  "published": "2024-10-16T08:15:06.160",
  "references": [
    {
      "url": "https://cloudstack.apache.org/blog/security-release-advisory-4.18.2.4-4.19.1.2",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "security@apache.org"
    },
    {
      "url": "https://cloudstack.apache.org/blog/security-release-advisory-4.18.2.4-4.19.1.2",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "security@apache.org"
    },
    {
      "url": "https://cloudstack.apache.org/blog/security-release-advisory-4.18.2.4-4.19.1.2",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "security@apache.org"
    },
    {
      "url": "https://cloudstack.apache.org/blog/security-release-advisory-4.18.2.4-4.19.1.2",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "security@apache.org"
    },
    {
      "url": "https://lists.apache.org/thread/ktsfjcnj22x4kg49ctock3d9tq7jnvlo",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "security@apache.org"
    },
    {
      "url": "http://www.openwall.com/lists/oss-security/2024/10/15/5",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security@apache.org",
      "description": [
        {
          "lang": "en",
          "value": "CWE-352"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Users logged into the Apache CloudStack's web interface can be tricked to submit malicious CSRF requests due to missing validation of the origin of the requests. This can allow an attacker to gain privileges and access to resources of the authenticated users and may lead to account takeover, disruption, exposure of sensitive data and compromise integrity of the resources owned by the user account that are managed by the platform.\n\nThis issue affects Apache CloudStack from 4.15.1.0 through 4.18.2.3 and 4.19.0.0 through 4.19.1.1\n\n\n\nUsers are recommended to upgrade to Apache CloudStack 4.18.2.4 or 4.19.1.2, or later, which addresses this issue."
    },
    {
      "lang": "es",
      "value": "Los usuarios que hayan iniciado sesión en la interfaz web de Apache CloudStack pueden ser engañados para que envíen solicitudes CSRF maliciosas debido a la falta de validación del origen de las solicitudes. Esto puede permitir que un atacante obtenga privilegios y acceso a los recursos de los usuarios autenticados y puede provocar la apropiación de cuentas, interrupciones, exposición de datos confidenciales y comprometer la integridad de los recursos propiedad de la cuenta de usuario que son administrados por la plataforma. Este problema afecta a Apache CloudStack desde la versión 4.15.1.0 hasta la 4.18.2.3 y desde la versión 4.19.0.0 hasta la 4.19.1.1. Se recomienda a los usuarios que actualicen a Apache CloudStack 4.18.2.4 o 4.19.1.2, o posterior, que soluciona este problema."
    }
  ],
  "lastModified": "2026-06-17T07:54:40.327",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:apache:cloudstack:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "174E314B-9CD8-445B-AE96-A9AC4D5D8B80",
              "versionEndExcluding": "4.18.2.4",
              "versionStartIncluding": "4.15.1.0"
            },
            {
              "criteria": "cpe:2.3:a:apache:cloudstack:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6B851F50-43E1-4DD1-989E-94676D12EC33",
              "versionEndExcluding": "4.19.1.2",
              "versionStartIncluding": "4.19.0.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security@apache.org"
}