github apache/cloudstack 4.18.2.4
Apache CloudStack 4.18.2.4 (LTS Security Release)

latest releases: 4.20.1.0, 4.19.3.0, 4.19.2.0...
11 months ago

This is a security release that fixes the following on top of the 4.18.2.3 release:

  • CVE-2024-45219: Uploaded and registered templates and volumes can be used to abuse KVM-based infrastructure
  • CVE-2024-45461: Access checks not enforced in Quota
  • CVE-2024-45462: Incomplete session invalidation on web interface logout
  • CVE-2024-45693: Request origin validation bypass makes account takeover possible

Advisory: https://cloudstack.apache.org/blog/security-release-advisory-4.18.2.4-4.19.1.2

Release notes: https://docs.cloudstack.apache.org/en/4.18.2.4/releasenotes
Installation docs: https://docs.cloudstack.apache.org/en/4.18.2.4/installguide
Upgrade docs: https://docs.cloudstack.apache.org/en/4.18.2.4/upgrading
Admin docs: https://docs.cloudstack.apache.org/en/4.18.2.4/adminguide
API docs: https://cloudstack.apache.org/api/apidocs-4.18

Don't miss a new cloudstack release

NewReleases is sending notifications on new releases.