Releases: apache/cloudstack
Apache CloudStack 4.18.2.1 (LTS Security Release)
This is a security release that fixes the following on top of the 4.18.2.0 release:
- CVE-2024-38346: Unauthenticated cluster service port leads to remote execution
- CVE-2024-39864: Integration API service uses dynamic port when disabled
Advisory: https://cloudstack.apache.org/blog/security-release-advisory-4.19.0.2-4.18.2.1
Release notes: https://docs.cloudstack.apache.org/en/4.18.2.1/releasenotes
Installation docs: https://docs.cloudstack.apache.org/en/4.18.2.1/installguide
Upgrade docs: https://docs.cloudstack.apache.org/en/4.18.2.1/upgrading
Admin docs: https://docs.cloudstack.apache.org/en/4.18.2.1/adminguide
API docs: https://cloudstack.apache.org/api/apidocs-4.18
Apache CloudStack 4.18.2.0 (LTS)
Release notes: https://docs.cloudstack.apache.org/en/4.18.2.0/releasenotes
Installation docs: https://docs.cloudstack.apache.org/en/4.18.2.0/installguide
Upgrade docs: https://docs.cloudstack.apache.org/en/4.18.2.0/upgrading
Admin docs: https://docs.cloudstack.apache.org/en/4.18.2.0/adminguide
API docs: https://cloudstack.apache.org/api/apidocs-4.18
Apache CloudStack 4.18.1.1 (LTS Security Release)
This is a security release the fixes the following on top of 4.18.1.0 release:
- CVE-2024-29006 x-forwarded-for parsed by default
- CVE-2024-29007 When downloading templates or ISOs, the UI/SSVM follow http redirects with potentially dangerous consequences
- CVE-2024-29008 The extraconfig feature can be abused to load hypervisor resources on a VM instance
Advisory: https://cloudstack.apache.org/blog/security-release-advisory-4.19.0.1-4.18.1.1
Apache CloudStack 4.19.0.1 (LTS Security Release)
This is a security release the fixes the following on top of 4.19.0.0 release:
- CVE-2024-29006 x-forwarded-for parsed by default
- CVE-2024-29007 When downloading templates or ISOs, the UI/SSVM follow http redirects with potentially dangerous consequences
- CVE-2024-29008 The extraconfig feature can be abused to load hypervisor resources on a VM instance
Advisory: https://cloudstack.apache.org/blog/security-release-advisory-4.19.0.1-4.18.1.1
Apache CloudStack 4.19.0.0 (LTS)
Release notes: https://docs.cloudstack.apache.org/en/4.19.0.0/releasenotes
Installation docs: https://docs.cloudstack.apache.org/en/4.19.0.0/installguide
Upgrade docs: https://docs.cloudstack.apache.org/en/4.19.0.0/upgrading
Admin docs: https://docs.cloudstack.apache.org/en/4.19.0.0/adminguide
API docs: https://cloudstack.apache.org/api/apidocs-4.19
Apache CloudStack 4.18.0.0 (LTS)
Release notes: https://docs.cloudstack.apache.org/en/4.18.0.0/releasenotes
Installation docs: https://docs.cloudstack.apache.org/en/4.18.0.0/installguide
Upgrade docs: https://docs.cloudstack.apache.org/en/4.18.0.0/upgrading
Admin docs: https://docs.cloudstack.apache.org/en/4.18.0.0/adminguide
API docs: https://cloudstack.apache.org/api/apidocs-4.18
Apache CloudStack 4.17.2.0 (LTS)
Release notes: https://docs.cloudstack.apache.org/en/4.17.2.0/releasenotes
Installation docs: https://docs.cloudstack.apache.org/en/4.17.2.0/installguide
Upgrade docs: https://docs.cloudstack.apache.org/en/4.17.2.0/upgrading
Admin docs: https://docs.cloudstack.apache.org/en/4.17.2.0/adminguide
API docs: https://cloudstack.apache.org/api/apidocs-4.17
Apache CloudStack 4.17.1.0 (LTS)
Release notes: https://docs.cloudstack.apache.org/en/4.17.1.0/releasenotes
Installation docs: https://docs.cloudstack.apache.org/en/4.17.1.0/installguide
Upgrade docs: https://docs.cloudstack.apache.org/en/4.17.1.0/upgrading
Admin docs: https://docs.cloudstack.apache.org/en/4.17.1.0/adminguide
API docs: https://cloudstack.apache.org/api/apidocs-4.17
Apache CloudStack 4.17.0.1 (LTS) Security Release
Release notes: https://docs.cloudstack.apache.org/en/4.17.0.0/releasenotes
Installation docs: https://docs.cloudstack.apache.org/en/4.17.0.0/installguide
Upgrade docs: https://docs.cloudstack.apache.org/en/4.17.0.0/upgrading
Admin docs: https://docs.cloudstack.apache.org/en/4.17.0.0/adminguide
API docs: https://cloudstack.apache.org/api/apidocs-4.17
Advisory:
https://blogs.apache.org/cloudstack/entry/cve-2022-35741
Apache CloudStack 4.16.1.1 (LTS) Security Release
Release notes: https://docs.cloudstack.apache.org/en/4.16.1.0/releasenotes
Installation docs: https://docs.cloudstack.apache.org/en/4.16.1.0/installguide
Upgrade docs: https://docs.cloudstack.apache.org/en/4.16.1.0/upgrading
Admin docs: https://docs.cloudstack.apache.org/en/4.16.1.0/adminguide
API docs: https://cloudstack.apache.org/api/apidocs-4.16
Advisory:
https://blogs.apache.org/cloudstack/entry/cve-2022-35741