Skip to content

Releases: apache/cloudstack

Apache CloudStack 4.18.2.1 (LTS Security Release)

05 Jul 13:31
Compare
Choose a tag to compare

This is a security release that fixes the following on top of the 4.18.2.0 release:

  • CVE-2024-38346: Unauthenticated cluster service port leads to remote execution
  • CVE-2024-39864: Integration API service uses dynamic port when disabled

Advisory: https://cloudstack.apache.org/blog/security-release-advisory-4.19.0.2-4.18.2.1

Release notes: https://docs.cloudstack.apache.org/en/4.18.2.1/releasenotes
Installation docs: https://docs.cloudstack.apache.org/en/4.18.2.1/installguide
Upgrade docs: https://docs.cloudstack.apache.org/en/4.18.2.1/upgrading
Admin docs: https://docs.cloudstack.apache.org/en/4.18.2.1/adminguide
API docs: https://cloudstack.apache.org/api/apidocs-4.18

Apache CloudStack 4.18.2.0 (LTS)

25 Apr 18:05
Compare
Choose a tag to compare

Apache CloudStack 4.18.1.1 (LTS Security Release)

04 Apr 05:23
4.18.1.1
Compare
Choose a tag to compare

This is a security release the fixes the following on top of 4.18.1.0 release:

  • CVE-2024-29006 x-forwarded-for parsed by default
  • CVE-2024-29007 When downloading templates or ISOs, the UI/SSVM follow http redirects with potentially dangerous consequences
  • CVE-2024-29008 The extraconfig feature can be abused to load hypervisor resources on a VM instance

Advisory: https://cloudstack.apache.org/blog/security-release-advisory-4.19.0.1-4.18.1.1

Apache CloudStack 4.19.0.1 (LTS Security Release)

04 Apr 05:23
4.19.0.1
Compare
Choose a tag to compare

This is a security release the fixes the following on top of 4.19.0.0 release:

  • CVE-2024-29006 x-forwarded-for parsed by default
  • CVE-2024-29007 When downloading templates or ISOs, the UI/SSVM follow http redirects with potentially dangerous consequences
  • CVE-2024-29008 The extraconfig feature can be abused to load hypervisor resources on a VM instance

Advisory: https://cloudstack.apache.org/blog/security-release-advisory-4.19.0.1-4.18.1.1

Apache CloudStack 4.19.0.0 (LTS)

06 Feb 07:42
Compare
Choose a tag to compare

Apache CloudStack 4.18.0.0 (LTS)

16 Mar 09:09
Compare
Choose a tag to compare

Apache CloudStack 4.17.2.0 (LTS)

16 Dec 15:29
4.17.2.0
Compare
Choose a tag to compare

Apache CloudStack 4.17.1.0 (LTS)

26 Sep 12:13
Compare
Choose a tag to compare

Apache CloudStack 4.17.0.1 (LTS) Security Release

18 Jul 14:17
4.17.0.1
Compare
Choose a tag to compare

Apache CloudStack 4.16.1.1 (LTS) Security Release

18 Jul 14:17
4.16.1.1
Compare
Choose a tag to compare