Instances deployed via the Proxmox extension allow unauthorized access to instances belonging to other tenants. This issue affects Apache CloudStack: from 4.21.0.0 through 4.22.0.0. The Proxmox extension for CloudStack improperly uses a user-editable instance setting, proxmox_vmid, to associate CloudStack instances with Proxmox virtual machines. Because this value is not restricted or validated against tenant ownership and Proxmox VM IDs are predictable, a non-privileged attacker can modify the setting to reference a VM belonging to another account. This allows unauthorized cross-tenant access and enables full control over the targeted VM, including starting, stopping, and destroying the virtual machine. Users are recommended to upgrade to version 4.22.0.1, which fixes this issue. As a workaround for the existing installations, editing of the proxmox_vmid instance detail by users can be prevented by adding this detail name to the global configuration parameter - user.vm.denied.details.
The Proxmox extension for CloudStack uses a user-editable instance parameter named proxmox_vmid to associate CloudStack instances with Proxmox virtual machines. This parameter is not validated for resource ownership by the tenant nor is it restricted from editing. Since VM identifiers in Proxmox are predictable, an unprivileged attacker can modify the proxmox_vmid value to point to a virtual machine belonging to another account. As a result, the attacker gains full control over the target virtual machine, including the ability to run, stop, and destroy it.
An attacker can gain unauthorized access to instances of other tenants and take full operational control over them — including running, stopping, and permanently deleting virtual machines. Both confidentiality and integrity of other users' data and resources are compromised.
It is recommended to update to version 4.22.0.1, which eliminates the vulnerability. As a workaround for existing installations, the proxmox_vmid parameter name should be added to the global user.vm.denied.details configuration, which will prevent users from editing this field.
Apache CloudStack in versions from 4.21.0.0 to 4.22.0.0 (inclusive) in deployments using the Proxmox extension
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:NApache Cloudstack
APPApache4.21.0.0 – 4.22.0.1 (excl.)
Related vulnerabilities
Improper Access Control vulnerability in Apache CloudStack's Kubernetes Service (CKS) plugin, allowing cross-t...
Improper Encoding or Escaping of Output vulnerability in Apache CloudStack's UI while using Instance Reset Pas...
Server-Side Request Forgery (SSRF) vulnerability in Apache CloudStack's webhook module, exploitable via webhoo...
Apache CloudStack — RCE przez niechroniony port integracyjny API
Apache CloudStack — RCE przez nieuwierzytelniony port klastra (9090)