product of apache

cloudstack

5 thingsrelated by NVD
Severity

Being told

Watch: its feed Ask more of it

The feed says each thing that enters, leaves or changes; a reader adds its address, /zetlyn/trackers/cve/things.atom?q=…, to theirs.

Every thing

Due to multiple time-of-check time-of-use race conditions in the resource count check and increment logic, as well as missing validations…
CVE-2025-69233
Severity medium
Missing MinIO policy cleanup on bucket deletion via Apache CloudStack allows users to retain access to buckets which they previously owned…
CVE-2025-66467
Severity high
The CloudStack Backup plugin has an improper access logic in versions 4.21.0.0 and 4.22.0.0. Anyone with authenticated user-account access…
CVE-2025-66172
Severity high
The CloudStack Backup plugin has an improper access logic in versions 4.21.0.0 and 4.22.0.0. Anyone with authenticated user-account access…
CVE-2025-66171
Severity medium
The CloudStack Backup plugin has an improper authorization logic in versions 4.21.0.0 and 4.22.0.0. Anyone with authenticated user-account…
CVE-2025-66170
Severity medium