6.5
/ 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Description
Due to multiple time-of-check time-of-use race conditions in the resource count check and increment logic, as well as missing validations, users of the platform are able to exceed the allocation limits configured for their accounts/domains. This can be used by an attacker to degrade the infrastructure's resources and lead to denial of service conditions.
Users are recommended to upgrade to Apache CloudStack versions 4.20.3.0 or 4.22.0.1, or later, which fixes this issue.
Users are recommended to upgrade to Apache CloudStack versions 4.20.3.0 or 4.22.0.1, or later, which fixes this issue.
Basic Information
ID
CVE-2025-69233
Source
apache
Published
May 8, 2026 at 12:19
Affected Product
Vendor
Apache Software Foundation
Product
Apache CloudStack
Version
4.0.0
Affected Versions
Apache Software Foundation Apache CloudStack 4.0.0
Apache Software Foundation Apache CloudStack 4.21.0.0
Apache Software Foundation Apache CloudStack 4.21.0.0