{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-06-13T20:14:08.187","vulnerabilities":[{"cve":{"id":"CVE-2024-29007","sourceIdentifier":"security@apache.org","published":"2024-04-04T08:15:06.970","lastModified":"2025-09-02T21:14:50.247","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"The CloudStack management server and secondary storage VM could be tricked into making requests to restricted or random resources by means of following 301 HTTP redirects presented by external servers when downloading templates or ISOs. Users are recommended to upgrade to version 4.18.1.1 or 4.19.0.1, which fixes this issue.\n\n"},{"lang":"es","value":"Se podría engañar al servidor de administración de CloudStack y a la máquina virtual de almacenamiento secundario para que realicen solicitudes a recursos restringidos o aleatorios mediante las siguientes redirecciones HTTP 301 presentadas por servidores externos al descargar plantillas o ISO. Se recomienda a los usuarios actualizar a la versión 4.18.1.1 o 4.19.0.1, que soluciona este problema."}],"metrics":{"cvssMetricV31":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","baseScore":7.3,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"LOW"},"exploitabilityScore":3.9,"impactScore":3.4}]},"weaknesses":[{"source":"security@apache.org","type":"Secondary","description":[{"lang":"en","value":"CWE-918"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-918"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:apache:cloudstack:*:*:*:*:*:*:*:*","versionStartIncluding":"4.9.1.0","versionEndExcluding":"4.18.1.1","matchCriteriaId":"B2EE4F78-B6F4-43CB-979E-BFFFFA139AD5"},{"vulnerable":true,"criteria":"cpe:2.3:a:apache:cloudstack:4.19.0.0:*:*:*:*:*:*:*","matchCriteriaId":"51E212EC-AC62-4533-B3B2-A660807F0C1F"}]}]}],"references":[{"url":"https://lists.apache.org/thread/82f46pv7mvh95ybto5hn8wlo6g8jhjvp","source":"security@apache.org","tags":["Mailing List","Vendor Advisory"]},{"url":"https://lists.apache.org/thread/82f46pv7mvh95ybto5hn8wlo6g8jhjvp","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mailing List","Vendor Advisory"]}]}}]}