Executive brief
Apache CloudStack is a cloud management platform used by organizations to provision and manage virtual infrastructure. A vulnerability in its OAuth2 authentication plugin exposes sensitive user information to unauthorized attackers, potentially compromising credentials and user sessions that control access to critical cloud resources.
Technical details
This vulnerability is an information disclosure flaw in Apache CloudStack's OAuth2 authentication plugin and Google OAuth integration. The vulnerability allows unauthorized actors to access sensitive information during the OAuth2 authentication flow. The issue affects versions 4.19.0.0 through 4.20.3.0 and 4.21.0.0 through 4.22.1.0. Patches are available in versions 4.20.3.1 and 4.22.1.1. The authentication nature of the component suggests the vulnerability is reachable to unauthenticated users during the login process.
Affected products
- Apache CloudStack 4.19.0.0 through 4.20.3.0, 4.21.0.0 through 4.22.1.0
Timeline
- 2026-08-21: disclosed
- 2026-08-21: patched: Fixes available in CloudStack 4.20.3.1 and 4.22.1.1