Patch Now: Apache CloudStack Plugs Proxmox and KVM Exploits in New LTS Release
ID: ff1b3989-58b2-5229-8cec-d3a3cd55c3bf
STIX ID: report--ff1b3989-58b2-5229-8cec-d3a3cd55c3bf
Feed Name: securityonline.info
Threat Score
Apache CloudStack published urgent LTS patches (4.20.3.0 and 4.22.0.1) addressing seven vulnerabilities — notably a Proxmox cross-tenant VM hijack, KVM host RCE, and multiple Backup plugin authorization flaws — that allow unauthorized VM control, hypervisor compromise, and restoration/creation of VMs from other accounts; administrators should upgrade or apply provided workarounds immediately.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
