Executive brief
Apache CloudStack is a cloud infrastructure management platform used by organizations to deploy and manage virtual computing resources. This vulnerability allows sensitive information stored in AsyncJob database records to be accessed in plaintext, exposing credentials and other confidential data to database administrators or anyone with database access. This could lead to unauthorized access to cloud infrastructure and compromise of customer workloads.
Technical details
This is a cleartext storage vulnerability affecting the AsyncJob storage mechanism in Apache CloudStack's database layer. Sensitive information that should be encrypted is instead stored in plaintext in AsyncJob records, making it accessible to any database user or attacker with database access. The vulnerability affects versions 4.0.0 through 4.20.3.0 and 4.21.0.0 through 4.22.1.0. No special authentication or network access is required beyond database access. The attack vector is primarily local/adjacent (database access), and the impact is information disclosure of sensitive credentials and configuration data. Patches are available in versions 4.20.3.1, 4.22.1.1, and later.
Affected products
- Apache CloudStack 4.0.0 through 4.20.3.0 and 4.21.0.0 through 4.22.1.0
Timeline
- 2026-08-21: disclosed