Executive brief
Apache CloudStack's OAuth authentication plugin exposes sensitive OAuth provider credentials and configuration details to unauthorized users. When an attacker lists OAuth providers through the vulnerable plugin, they can retrieve configuration information that should remain confidential, potentially compromising authentication systems and allowing further attacks against cloud infrastructure.
Technical details
An information disclosure vulnerability exists in Apache CloudStack's OAuth authentication plugin when listing OAuth providers. The vulnerability allows an unauthenticated or low-privileged attacker to enumerate and retrieve sensitive OAuth provider details including credentials and configuration through the provider listing functionality. The issue affects CloudStack versions 4.19.0.0–4.20.3.0 and 4.21.0.0–4.22.1.0. Patches are available in versions 4.20.3.1 and 4.22.1.1 or later.
Affected products
- Apache CloudStack 4.19.0.0–4.20.3.0 and 4.21.0.0–4.22.1.0
Timeline
- 2026-08-21: disclosed
- 2026-08-21: patched: Fixes available in versions 4.20.3.1 and 4.22.1.1 or later